¢¡¤£¦¥§£¦¥©¨ ¢¡ ¨ ©¡¤ ¤ "!"#%$&$(')$(*©+-,.,"/10123!547698&,":$(;(6< ,.=&8?>A@BDCFEHGIKJ¤LK¥>NMOEQPR¨J
S
¥UTV¡¤>?¨J¤WDX¤E YZ¨J¤¥1J¤>? ¢[ \M©¥¥U>^]`__aE
b(¢c¤1¡¤Z£¦J¤U7¨£¦J¤>&¥UKedfd3dhgUifjfikhg1lOjm3nhg1ofdOjmfpfkOqfr3rsgUifjRtnOj3i
¢[ uM©UK¥¥ ¡¤¨¥wvU¨JKWx¡¤7y¦y¦Vz{£¦J¤v|¥ AKTK£¦}¤T~ O7£¦¥¥£¦J¤¥ ¡¤~Ky¦KTUJ¤£¦TwP¤K¥U£QJ?¡¤£¦¥
@ARf
M.K7£¦¥¥U£J-£¦¥^vQ¨JW{U£PHK>O ¤£¦J ¨J W¥Z¨¥U£J vyFTK B|f¡¤£¦¥^TV¡¤¨Q ^
AKU¥J¤¨Qyc ¥KE ¢¡¤£¥ O7£¦¥¥£¦JW R¥ J¤`3KJ¤WDD@¤£J W¤£J v c y£ ¤y¦TV¡ ¨ ¥Q
¡¤@A3f> ¡¤3TKQ BO£¦J¤vIw ¤URW c¤TK£¦J¤v T ¤£¦K¥{w¡ K¢¡¤¨J AK¥UJ¤¨y©c¤¥U¡¤
AKU¥J5TK¨`£¦J¤v¡ TK B>¢7¨f£¦J¤vKy¦KTQJ¤£T-T ¤£¦K¥¨PR¨£¦y¨Q@¤y U£¦PR¨y^@B
¡¤KU¥sz{£¡¤c ¤U£h AKU~£¦¥¥U£QJ £¦J7z{U££J¤v~Q ¢[ MUK¥U¥E
&OTKK <z{¡¤KUPHK1VU£W¤W KJ@B¡¤¥U OTK£¦}¤T- O7£¦¥¥£¦J5¨@APH>¡¤¥1¨J W¤¨WTK BO£¦v¡xJ¤£T
Q ¢[ \M©UK¥¥Z¨ ¤ y£¦K¥%¡ £¥hKy¦KTUJ¤£¦ThP¤K¥U£QJ¤
FK£¡¤¡¤£¥§@O3J §¨QJBD ¨F7¨B @AZK 3W¤c¤TKW&U¨J¤¥U~£KW£¦J¨QJBDQu
@B¨JB7K¨QJ¤¥>hKy¦KTUJ¤£¦T7TV¡¤¨J¤£¦TK¨y¦>h£J TKy¦c¤W¤£¦J¤v ¤¡¤RT BN£¦J¤v>¢7£¦TKU}¤y¦~£¦J¤v>
¨J WKTW £J¤vQ>%@B5¨JB£J¤Q7¨£¦J¥1U¨ve£¦PR¨ys¥1BO¥7>?z{£¡ c~ ¤U£
AKU~£¦¥¥U£QJ £¦J7z{U££J¤v~Q ¡ { c¤@¤y¦£¥U¡¤KUE
¢¡¤7TJ¤¥JQ§ ¢[ M©¥¥{W¤R¥ J¤~3KJ¤Wx-T BN£¦J¤vD vJ¤KU¨ysW¤£¦¥£¦@¤c£¦J¤>
§ ¤Q~`£¦J¤>NQ§TK¨`£¦J¤vJ¤z¡zef¥>N^§¥¨y¦KEhX¤ AKT£}¤Te O7£¥U¥£¦Jxc¤¥1{@O
@<¨£¦J¤KWD£¦J7z{U££J¤v~Q ¢[ \M©UK¥¥Z¢¥Uc¤TV¡ T BN£¦J¤vE
¢
T ]__Q£@B ¢[^ ¤M©¥¥>¥¦J¤TE Chapter
Number-Theoretic Reference Problems
Contents in Brief
3.1 Introduction and overview §?§&§?§?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 87
3.2 The integer factorization problem §&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 89
3.3 The RSA problem §?§?§&§?§?§?§&§?§?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 98
3.4 The quadratic residuosity problem §&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 99
3.5 Computing square roots in ¨ª©«§?§?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 99
3.6 The discrete logarithm problem §?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 103
3.7 The Dif®e-Hellman problem §&§?§?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 113
3.8 Composite moduli §?§?§&§?§?§?§&§?§?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 114
3.9 Computing individual bits §?§&§?§?§&§?§?§?§&§?§?§?§N§?§?§&§?§?§?§&§ 114
3.10 The subset sum problem §?§?§&§?§?§&§?§?§?§&§?§?§?§N§?§?