We also improve on prior constructions of factoring-based smooth universal hashing, in that our constructions *do not require that the underlying RSA modulus is a product of safe primes*. (This holds for the schemes based on the Quadratic Residuosity Assumption as well as the ones based on the $N$'th Residuosity Assumption.) In fact, we observe that the safe-prime requirement is unnecessary for many prior constructions. In particular, the factoring-based CCA secure encryption schemes due to Cramer-Shoup, Gennaro-Lindell, and Camenisch-Shoup remain secure even if the underlying RSA modulus is not a product of safe primes.
Category / Keywords: public-key cryptography / CCA-secure encryption, Oblivious Transfer, Safe primes, Smooth Projective Hashing Publication Info: Full version to appear in Journal of Cryptology Date: received 30 Mar 2007, last revised 31 Oct 2010 Contact author: shaih at alum mit edu Available format(s): PDF | BibTeX Citation Version: 20101031:093948 (All versions of this report) Short URL: ia.cr/2007/118 Discussion forum: Show discussion | Start new discussion