{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T03:19:44Z","timestamp":1776827984760,"version":"3.51.2"},"publisher-location":"Berlin, Heidelberg","reference-count":48,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540440505","type":"print"},{"value":"9783540457084","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2002]]},"DOI":"10.1007\/3-540-45708-9_28","type":"book-chapter","created":{"date-parts":[[2007,10,19]],"date-time":"2007-10-19T08:48:16Z","timestamp":1192783696000},"page":"433-448","source":"Crossref","is-referenced-by-count":14,"title":["Hidden Number Problem with the Trace and Bit Security of XTR and LUC"],"prefix":"10.1007","author":[{"given":"Wen-Ching W.","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mats","family":"N\u00e4slund","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor E.","family":"Shparlinski","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2002,9,13]]},"reference":[{"key":"28_CR1","doi-asserted-by":"crossref","unstructured":"M. Ajtai, R. Kumar and D. Sivakumar, A sieve algorithm for the shortest lattice vector problem, Proc. 33rd ACM Symp. on Theory of Comput., Crete, Greece, July 6\u20138, 2001, 601\u2013610.","DOI":"10.1145\/380752.380857"},{"key":"28_CR2","unstructured":"D. Bleichenbacher, W. Bosma and A. K. Lenstra, Some remarks on Lucas-based Cryptograph, Lect. Notes in Comp. Sci., Springer-Verlag, 963 (1995), 386\u2013396."},{"issue":"4","key":"28_CR3","doi-asserted-by":"publisher","first-page":"850","DOI":"10.1137\/0213053","volume":"13","author":"M. Blum","year":"1984","unstructured":"M. Blum and S. Micali, How to Generate Cryptographically Strong Sequences of Pseudo-random Bits, SIAM J. on Computing, 13(4), 850\u2013864, 1984.","journal-title":"SIAM J. on Computing"},{"key":"28_CR4","unstructured":"D. Boneh and R. Venkatesan, Hardness of computing the most significant bits of secret keys in Diffie-Hellman and related schemes, Lect. Notes in Comp. Sci., Springer-Verlag, 1109 (1996), 129\u2013142."},{"key":"28_CR5","unstructured":"D. Boneh and R. Venkatesan, Rounding in lattices and its cryptographic applications, Proc. 8th Annual ACM-SIAM Symp. on Discr. Algorithms, ACM, NY, 1997, 675\u2013681."},{"key":"28_CR6","unstructured":"A. E. Brouwer, R. Pellikaan and E. R. Verheul, Doing more with fewer bits, Lect. Notes in Comp. Sci., Springer-Verlag, 1716 (1999), 321\u2013332."},{"key":"28_CR7","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1007\/s11856-000-1270-1","volume":"120","author":"R. Canetti","year":"2000","unstructured":"R. Canetti, J. B. Friedlander, S. Konyagin, M. Larsen, D. Lieman and I. E. Shparlinski, On the statistical properties of Diffie-Hellman distributions, Israel J. Math., 120 (2000), 23\u201346.","journal-title":"Israel J. Math"},{"key":"28_CR8","doi-asserted-by":"crossref","unstructured":"P. Deligne, Cohomologie 'etale (SGA 41\/2 ), Lect. Notes in Math., Springer-Verlag, 569 (1977).","DOI":"10.1007\/BFb0091516"},{"key":"28_CR9","unstructured":"E. El Mahassni, P. Q. Nguyen and I. E. Shparlinski, The insecurity of Nyberg-Rueppel and other DSA-like signature schemes with partially known nonces, Lect. Notes in Comp. Sci., Springer-Verlag, 2146 (2001), 97\u2013109."},{"key":"28_CR10","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1023\/A:1008383811226","volume":"16","author":"J. B. Friedlander","year":"1999","unstructured":"J. B. Friedlander, M. Larsen, D. Lieman and I. E. Shparlinski, On correlation of binary M-sequences, Designs, Codes and Cryptography, 16 (1999), 249\u2013256.","journal-title":"Designs, Codes and Cryptography"},{"key":"28_CR11","doi-asserted-by":"crossref","unstructured":"M. I. Gonz\u00e1lez Vasco and I. E. Shparlinski, On the security of Diffie-Hellman bits, Proc. Workshop on Cryptography and Computational Number Theory, Singapore 1999, Birkh\u00e4user, 2001, 257\u2013268.","DOI":"10.1007\/978-3-0348-8295-8_19"},{"key":"28_CR12","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1090\/S0025-5718-01-01358-8","volume":"71","author":"M. I. G. Vasco","year":"2002","unstructured":"M. I. Gonz\u00e1lez Vasco and I. E. Shparlinski, Security of the most significant bits of the Shamir message passing scheme, Math. Comp., 71 (2002), 333\u2013342.","journal-title":"Math. Comp."},{"key":"28_CR13","unstructured":"J. H\u00f8astad and M. N\u00e4slund, The Security of all RSA and discrete log bits, Electronic Colloquium on Computational Complexity, Report TR99-037, 1999. (To appear in Jorunal of the ACM)"},{"key":"28_CR14","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1023\/A:1011214926272","volume":"23","author":"N. A. Howgrave-Graham","year":"2001","unstructured":"N. A. Howgrave-Graham and N. P. Smart, Lattice attacks on digital signature schemes, Designs, Codes and Cryptography, 23 (2001), 283\u2013290.","journal-title":"Designs, Codes and Cryptography"},{"key":"28_CR15","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1146\/annurev.cs.02.060187.001311","volume":"2","author":"R. Kannan","year":"1987","unstructured":"R. Kannan, Algorithmic geometry of numbers, Annual Review of Comp. Sci., 2 (1987), 231\u2013267.","journal-title":"Annual Review of Comp. Sci."},{"key":"28_CR16","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1287\/moor.12.3.415","volume":"12","author":"R. Kannan","year":"1987","unstructured":"R. Kannan, Minkowski\u2019s convex body theorem and integer programming, Math. of Oper. Research, 12 (1987), 231\u2013267.","journal-title":"Math. of Oper. Research"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"N. M. Katz, Gauss sums, Kloosterman sums, and monodromy groups, Ann. of Math. Studies, 116, Princeton Univ. Press, 1988.","DOI":"10.1515\/9781400882120"},{"key":"28_CR18","doi-asserted-by":"publisher","first-page":"203","DOI":"10.2307\/2007884","volume":"48","author":"N. Koblitz","year":"1987","unstructured":"N. Koblitz, Elliptic curve cryptosystems, Math. Comp., 48, 203\u2013209, 1987.","journal-title":"Math. Comp."},{"key":"28_CR19","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9780511542930","volume-title":"Character sums with exponential functions and their applications","author":"S. V. Konyagin","year":"1999","unstructured":"S. V. Konyagin and I. E. Shparlinski, Character sums with exponential functions and their applications, Cambridge Univ. Press, Cambridge, 1999."},{"key":"28_CR20","doi-asserted-by":"crossref","unstructured":"A. K. Lenstra Unbelievable security. Matching AES security using public key systems, Lect. Notes in Comp. Sci., Springer-Verlag, 2248 (2001), 67\u201386.","DOI":"10.1007\/3-540-45682-1_5"},{"key":"28_CR21","doi-asserted-by":"publisher","first-page":"515","DOI":"10.1007\/BF01457454","volume":"261","author":"A. K. Lenstra","year":"1982","unstructured":"A. K. Lenstra, H. W. Lenstra and L. Lov\u00e1sz, Factoring polynomials with rational coefficients, Mathematische Annalen, 261 (1982), 515\u2013534.","journal-title":"Mathematische Annalen"},{"key":"28_CR22","unstructured":"A. K. Lenstra and M. Stam, Speeding up XTR, Lect. Notes in Comp. Sci., Springer-Verlag, 2248 (2001), pp. 125\u2013143."},{"key":"28_CR23","unstructured":"A. K. Lenstra and E. R. Verheul, The XTR public key system, Lect. Notes in Comp. Sci., Springer-Verlag, 1880 (2000), 1\u201319."},{"key":"28_CR24","unstructured":"A. K. Lenstra and E. R. Verheul, Key improvements to XTR, Lect. Notes in Comp. Sci., Springer-Verlag, 1976 (2000), 220\u2013233."},{"key":"28_CR25","doi-asserted-by":"crossref","unstructured":"A. K. Lenstra and E. R. Verheul, An overview of the XTR public key system, Proc. the Conf. on Public Key Cryptography and Computational Number Theory, Warsaw 2000, Walter de Gruyter, 2001, 151\u2013180.","DOI":"10.1515\/9783110881035.151"},{"key":"28_CR26","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1016\/0022-314X(92)90120-E","volume":"41","author":"W.-C. W. Li","year":"1992","unstructured":"W.-C. W. Li, Character sums and abelian Ramanujan graphs, J. Number Theory, 41 (1992), 199\u2013217.","journal-title":"J. Number Theory"},{"key":"28_CR27","doi-asserted-by":"crossref","DOI":"10.1142\/2716","volume-title":"Number theory with applications","author":"W.-C. W. Li","year":"1996","unstructured":"W.-C. W. Li, Number theory with applications, World Scientific, Singapore, 1996."},{"key":"28_CR28","volume-title":"Finite fields","author":"R. Lidl","year":"1997","unstructured":"R. Lidl and H. Niederreiter, Finite fields, Cambridge University Press, Cambridge, 1997."},{"issue":"2","key":"28_CR29","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1137\/0217021","volume":"17","author":"D. L. Long","year":"1988","unstructured":"D. L. Long and A. Wigderson, The discrete log hides O(log n) bits, SIAM J. on Computing, 17(2):413\u2013420, 1988.","journal-title":"SIAM J. on Computing"},{"key":"28_CR30","unstructured":"D. Micciancio, On the hardness of the shortest vector problem, PhD Thesis, MIT, 1998."},{"key":"28_CR31","unstructured":"V. Miller, Uses of elliptic curves in cryptography, Lect. Notes in Comp. Sci., Springer-Verlag, 218 (1986), 417\u2013426."},{"key":"28_CR32","doi-asserted-by":"crossref","unstructured":"P. Q. Nguyen, The dark side of the Hidden Number Problem: Lattice attacks on DSA, Proc. Workshop on Cryptography and Computational Number Theory, Singapore 1999, Birkh\u00e4user, 2001, 321\u2013330.","DOI":"10.1007\/978-3-0348-8295-8_23"},{"key":"28_CR33","doi-asserted-by":"crossref","unstructured":"P. Q. Nguyen and I. E. Shparlinski, The insecurity of the Digital Signature Algorithm with partially known nonces, J. Cryptology, (to appear).","DOI":"10.1007\/s00145-002-0021-3"},{"key":"28_CR34","unstructured":"P. Q. Nguyen and I. E. Shparlinski, The insecurity of the elliptic curve Digital Signature Algorithm with partially known nonces, Designs, Codes and Cryptography, (to appear)."},{"key":"28_CR35","unstructured":"P. Q. Nguyen and J. Stern, Lattice reduction in cryptology: An update, Lect. Notes in Comp. Sci., Springer-Verlag, 1838 (2000), 85\u2013112."},{"key":"28_CR36","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1007\/3-540-44670-2_12","volume":"2146","author":"P. Q. Nguyen","year":"2001","unstructured":"P. Q. Nguyen and J. Stern, The two faces of lattices in cryptology, Springer-Verlag, 2146 (2001), 146\u2013180.","journal-title":"The two faces of lattices in cryptology"},{"key":"28_CR37","doi-asserted-by":"crossref","unstructured":"H. Niederreiter, Random number generation and Quasi-Monte Carlo methods, SIAM Press, 1992.","DOI":"10.1137\/1.9781611970081"},{"key":"28_CR38","first-page":"62","volume":"219","author":"R. Peralta","year":"1986","unstructured":"R. Peralta, Simultaneous security of bits in the discrete log, Lect. Notes in Comp. Sci., Springer-Verlag, 219 (1986), 62\u201372.","journal-title":"Simultaneous security of bits in the discrete log"},{"key":"28_CR39","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1109\/TIT.1978.1055817","volume":"24","author":"S. C. Pohlig","year":"1978","unstructured":"S. C. Pohlig and M. Hellman, An improved algorithm for computing logarithms over GF(p), IEEE Transactions on Information Theory, IT-24 (1):106\u2013110, 1978.","journal-title":"IEEE Transactions on Information Theory"},{"key":"28_CR40","unstructured":"K. Prachar, Primzahlverteilung, Springer-Verlag, 1957."},{"key":"28_CR41","doi-asserted-by":"crossref","unstructured":"C. P. Schnorr, A hierarchy of polynomial time basis reduction algorithms, Theor. Comp. Sci., 53 (1987), 201\u2013224.","DOI":"10.1016\/0304-3975(87)90064-8"},{"key":"28_CR42","unstructured":"C. P. Schnorr, Security of almost all discrete log bits, Electronic Colloquium on Computational Complexity, Report TR98-033, 1998."},{"key":"28_CR43","unstructured":"I. E. Shparlinski, Security of polynomial transformations of the Diffie-Hellman key, Preprint, 2000, 1\u20138."},{"key":"28_CR44","doi-asserted-by":"crossref","unstructured":"I. E. Shparlinski, Sparse polynomial approximation in finite fields, Proc. 33rd ACM Symp. on Theory of Comput., Crete, Greece, July 6\u20138, 2001, 209\u2013215.","DOI":"10.1145\/380752.380803"},{"key":"28_CR45","unstructured":"I. E. Shparlinski, On the generalised hidden number problem and bit security of XTR, Lect. Notes in Comp. Sci., Springer-Verlag, 2227 (2001), 268\u2013277."},{"key":"28_CR46","unstructured":"A. W. Schrift and A. Shamir, On the universality of the next bit test, Lect. Notes in Comp. Sci., Springer-Verlag, 537 (1990), 394\u2013408."},{"key":"28_CR47","unstructured":"P. J. Smith and C. T. Skinner, A public-key cryptosystem and a digital signature system based on the Lucas function analogue to discrete logarithms, Lect. Notes in Comp. Sci., Springer-Verlag, 917 (1995), 357\u2013364."},{"key":"28_CR48","unstructured":"E. R. Verheul, Certificates of recoverability with scalable recovery agent security, Lect. Notes in Comp. Sci., Springer-Verlag, 1751 (2000), 258\u2013275."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2014 CRYPTO 2002"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/3-540-45708-9_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,3]],"date-time":"2019-05-03T21:27:39Z","timestamp":1556918859000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/3-540-45708-9_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2002]]},"ISBN":["9783540440505","9783540457084"],"references-count":48,"URL":"https:\/\/doi.org\/10.1007\/3-540-45708-9_28","relation":{},"ISSN":["0302-9743"],"issn-type":[{"value":"0302-9743","type":"print"}],"subject":[],"published":{"date-parts":[[2002]]}}}