Advances in Cryptology — CRYPTO ’91, p. 252-266
Full text: Download
Three new trapdoor one-way functions are proposed that are based on elliptic curves over the ring ℤ n . The first class of functions is a naive construction, which can be used only in a digital signature scheme, and not in a public-key cryptosystem. The second, preferred class of function, does not suffer from this problem and can be used for the same applications as the RSA trapdoor one-way function, including zero-knowledge identification protocols. The third class of functions has similar properties to the Rabin trapdoor one-way functions. Although the security of these three schemes is based on the difficulty of factoring n, like the RSA and Rabin schemes, the schemes proposed seem to be more secure than those other schemes from the viewpoint of attacks without factoring such as low multiplier attacks. The new schemes are somewhat less efficient than the RSA and Rabin schemes.