supported by the National Natural Science Foundation of China (Grant No. 60970154);the National Basic Research Program of China (Grant No. 2007CB311202)
In this paper, we re-examine the bit security of Paillier's trapdoor function. We show that given a random w = gcyN rood N2EZN2 the most significant bit of its class c is a hard-core predicate, under a standard assum...