{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,7]],"date-time":"2026-02-07T22:09:14Z","timestamp":1770502154784,"version":"3.49.0"},"publisher-location":"Berlin, Heidelberg","reference-count":39,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540658894","type":"print"},{"value":"9783540489108","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[1999]]},"DOI":"10.1007\/3-540-48910-x_8","type":"book-chapter","created":{"date-parts":[[2007,10,10]],"date-time":"2007-10-10T13:57:35Z","timestamp":1192024655000},"page":"107-122","source":"Crossref","is-referenced-by-count":151,"title":["Proving in Zero-Knowledge that a Number is the Product of Two Safe Primes"],"prefix":"10.1007","author":[{"given":"Jan","family":"Camenisch","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Markus","family":"Michels","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[1999,4,15]]},"reference":[{"key":"8_CR1","doi-asserted-by":"crossref","unstructured":"E. Bach and J. Shallit. Factoring with cyclotomic polynomials. In 26th FOCS, IEEE, pp. 443\u2013450, 1985.","DOI":"10.1109\/SFCS.1985.24"},{"issue":"3","key":"8_CR2","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/BF00196727","volume":"4","author":"J. Boyar","year":"1991","unstructured":"J. Boyar, K. Friedl, and C. Lund. Practical zero-knowledge proofs: Giving hints and using defficiencies. Journal of Cryptology, 4(3):185\u2013206, 1991.","journal-title":"Journal of Cryptology"},{"key":"8_CR3","doi-asserted-by":"crossref","unstructured":"S. Brands. Untraceable on-line cash in wallets with observers. In Advances in Cryptology \u2014 CRYPTO\u2019 93, volume 773 of LNCS, pp. 302\u2013318, 1993.","DOI":"10.1007\/3-540-48329-2_26"},{"key":"8_CR4","doi-asserted-by":"crossref","unstructured":"S. Brands. Rapid demonstration of linear relations connected by boolean operators. In Advances in Cryptology \u2014 EUROCRYPT\u2019 97, volume 1233 of LNCS, pp. 318\u2013333. Springer Verlag, 1997.","DOI":"10.1007\/3-540-69053-0_22"},{"issue":"2","key":"8_CR5","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1016\/0022-0000(88)90005-0","volume":"37","author":"G. Brassard","year":"1988","unstructured":"G. Brassard, D. Chaum, and C. Cr\u00e9peau. Minimum disclosure proofs of knowledge. Journal of Computer and System Sciences, 37(2):156\u2013189, Oct. 1988.","journal-title":"Journal of Computer and System Sciences"},{"key":"8_CR6","doi-asserted-by":"crossref","unstructured":"J. Camenisch and M. Michels. Proving in zero-knowledge that a number n is the product of two safe primes. Technical Report RS-98-29, BRICS, Departement of Computer Science, University of \u00c5arhus, Nov. 1998.","DOI":"10.7146\/brics.v5i29.19435"},{"key":"8_CR7","unstructured":"J. Camenisch and M. Michels. A group signature scheme based on an RSA-variant. Tech. Rep. RS-98-27, BRICS, Departement of Computer Science, University of \u00c5arhus, Nov. 1998. Preliminary version appeared in Advances in Cryptology \u2014 ASIACRYPT\u2019 98, volume 1514 of LNCS, pages 160\u2013174. Springer Verlag, 1998."},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"J. Camenisch and M. Stadler. Efficient group signature schemes for large groups. In Advances in Cryptology \u2014 CRYPTO\u2019 97, volume 1296 of LNCS, pp. 410\u2013424. Springer Verlag, 1997.","DOI":"10.1007\/BFb0052252"},{"key":"8_CR9","unstructured":"J. Camenisch and M. Stadler. Proof systems for general statements about discrete logarithms. Technical Report TR 260, Institute for Theoretical Computer Science, ETH Z\u00fcrich, Mar. 1997."},{"key":"8_CR10","unstructured":"J. L. Camenisch. Group Signature Schemes and Payment Systems Based on the Discrete Logarithm Problem. PhD thesis, ETH Z\u00fcrich, 1998. Diss. ETH No. 12520."},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"A. Chan, Y. Frankel, and Y. Tsiounis. Easy come \u2014 easy go divisible cash. In Advances in Cryptology \u2014 EUROCRYPT\u2019 98, volume 1403 of LNCS, pp. 561\u2013575. Springer Verlag, 1998. Revised version available as GTE Technical Report.","DOI":"10.1007\/BFb0054154"},{"key":"8_CR12","doi-asserted-by":"crossref","unstructured":"D. Chaum, J.-H. Evertse, and J. van de Graaf. An improved protocol for demonstrating possession of discrete logarithms and some generalizations. In Advances in Cryptology \u2014 EUROCRYPT\u2019 87, volume 304 of LNCS, pp. 127\u2013141. Springer-Verlag, 1988.","DOI":"10.1007\/3-540-39118-5_13"},{"key":"8_CR13","doi-asserted-by":"crossref","unstructured":"D. Chaum, J.-H. Evertse, J. van de Graaf, and R. Peralta. Demonstrating possession of a discrete logarithm without revealing it. In Advances in Cryptology \u2014 CRYPTO\u2019 86, volume 263 of LNCS, pp. 200\u2013212. Springer-Verlag, 1987.","DOI":"10.1007\/3-540-47721-7_14"},{"key":"8_CR14","doi-asserted-by":"crossref","unstructured":"D. Chaum and T. P. Pedersen. Wallet databases with observers. In Advances in Cryptology \u2014 CRYPTO\u2019 92, volume 740 of LNCS, pp. 89\u2013105. Springer-Verlag, 1993.","DOI":"10.1007\/3-540-48071-4_7"},{"key":"8_CR15","volume-title":"Number 138 in Graduate Texts in Mathematics","author":"H. Cohen","year":"1993","unstructured":"H. Cohen. A Course in Computational Algebraic Number Theory. Number 138 in Graduate Texts in Mathematics. Springer-Verlag, Berlin, 1993."},{"key":"8_CR16","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"424","DOI":"10.1007\/BFb0055745","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 98","author":"R. Cramer","year":"1998","unstructured":"R. Cramer and I. Damg\u00e5rd. Zero-knowledge proof for finite field arithmetic, or: Can zero-knowledge be for free? In Advances in Cryptology \u2014 CRYPTO\u2019 98, volume 1642 of LNCS, pp. 424\u2013441, Berlin, 1998. Springer Verlag."},{"key":"8_CR17","doi-asserted-by":"crossref","unstructured":"R. Cramer, I. Damg\u00e5rd, and B. Schoenmakers. Proofs of partial knowledge and simplified design of witness hiding protocols. In Advances in Cryptology \u2014 CRYPTO\u2019 94, volume 839 of LNCS, pp. 174\u2013187. Springer Verlag, 1994.","DOI":"10.1007\/3-540-48658-5_19"},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"E. Fujisaki and T. Okamoto. Statistical zero knowledge protocols to prove modular polynomial relations. In Advances in Cryptology \u2014 CRYPTO\u2019 97, volume 1294 of LNCS, pp. 16\u201330. Springer Verlag, 1997.","DOI":"10.1007\/BFb0052225"},{"key":"8_CR19","doi-asserted-by":"crossref","unstructured":"E. Fujisaki and T. Okamoto. A practical and provably secure scheme for publicly verifiable secret sharing and its applications. In Advances in Cryptology \u2014 EUROCRYPT\u2019 98, volume 1403 of LNCS, pp. 32\u201346. Springer Verlag, 1998.","DOI":"10.1007\/BFb0054115"},{"key":"8_CR20","doi-asserted-by":"crossref","unstructured":"R. Gennaro, S. Jarecki, H. Krawczyk, and T. Rabin. Robust and efficient sharing of RSA functions. In Advances in Cryptology \u2014 CRYPT0\u2019 96, volume 1109 of LNCS, pp. 157\u2013172, Berlin, 1996. IACR, Springer Verlag.","DOI":"10.1007\/3-540-68697-5_13"},{"key":"8_CR21","doi-asserted-by":"crossref","unstructured":"R. Gennaro, H. Krawczyk, and T. Rabin. RSA-based undeniable signatures. In Advances in Cryptology \u2014 CRYPTO\u2019 97, volume 1296 of LNCS, pp. 132\u2013149. Springer Verlag, 1997.","DOI":"10.1007\/BFb0052232"},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"R. Gennaro, D. Micciancio, and T. Rabin. An efficient non-interactive statistical zero-knowledge proof system for quasi-safe prime products. In 5rd ACM Conference on Computer and Communicatons Security, 1998.","DOI":"10.1145\/288090.288108"},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"O. Goldreich, S. Micali, and A. Wigderson. How to prove all NP statements in zero-knowledge and a methodology of cryptographic protocol design. In Advances in Cryptology \u2014 CRYPTO\u2019 86, volume 263 of LNCS, pp. 171\u2013185. Springer-Verlag, 1987.","DOI":"10.1007\/3-540-47721-7_11"},{"issue":"12","key":"8_CR24","doi-asserted-by":"publisher","first-page":"514","DOI":"10.1049\/el:19840357","volume":"20","author":"J. Gordon","year":"1984","unstructured":"J. Gordon. Strong RSA keys. Electronics Letters, 20(12):514\u2013516, 1984.","journal-title":"Electronics Letters"},{"key":"8_CR25","doi-asserted-by":"crossref","unstructured":"K. Koyama, U. Maurer, T. Okamoto, and S. Vanstone. New public-key schemes based on elliptic curves over the ring Zn. In Advances in Cryptology \u2014 CRYPTO\u2019 91, volume 576 of LNCS, pp. 252\u2013266. Springer-Verlag, 1992.","DOI":"10.1007\/3-540-46766-1_20"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"E. Kranakis. Primality and Cryptography. Wiley-Teubner Series in Computer Science, 1986.","DOI":"10.1007\/978-3-322-96647-6"},{"issue":"2","key":"8_CR27","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1137\/0211029","volume":"11","author":"D. J. Lehmann","year":"1982","unstructured":"D. J. Lehmann. On primality tests. SIAM Journal of Computing, 11(2):374\u2013375, May 1982.","journal-title":"SIAM Journal of Computing"},{"key":"8_CR28","unstructured":"M. Liskov and B. Silverman. A Statisical limited-knowledge proof for secure RSA keys. manuscript, (1998)."},{"key":"8_CR29","unstructured":"W. Mao. Verifable Partial Sharing of Integer Factors. to appear in Proc. SAC\u2019 98, 1998."},{"key":"8_CR30","doi-asserted-by":"crossref","first-page":"300","DOI":"10.1016\/S0022-0000(76)80043-8","volume":"13","author":"G. L. Miller","year":"1976","unstructured":"G. L. Miller. Riemann\u2019s hypothesis and tests for primality. Journal of Computer and System Sciences, 13:300\u2013317, 1976.","journal-title":"Journal of Computer and System Sciences"},{"key":"8_CR31","doi-asserted-by":"crossref","unstructured":"T. P. Pedersen. Non-interactive and information-theoretic secure verifiable secret sharing. In Advances in Cryptology \u2014 CRYPTO\u2019 91, volume 576 of LNCS, pp. 129\u2013140. Springer Verlag, 1992.","DOI":"10.1007\/3-540-46766-1_9"},{"key":"8_CR32","doi-asserted-by":"publisher","first-page":"521","DOI":"10.1017\/S0305004100049252","volume":"76","author":"J. M. Pollard","year":"1974","unstructured":"J. M. Pollard. Theorems on factorization and primality testing. Proc. Cambridge Philosophical Society, 76:521\u2013528, 1974.","journal-title":"Proc. Cambridge Philosophical Society"},{"key":"8_CR33","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1016\/0022-314X(80)90084-0","volume":"12","author":"M. O. Rabin","year":"1980","unstructured":"M. O. Rabin. Probabilistic algorithm for testing primality. Journal of Number Theory, 12:128\u2013138, 1980.","journal-title":"Journal of Number Theory"},{"key":"8_CR34","doi-asserted-by":"crossref","unstructured":"A. de Santis, L. di Crescenzo, G. Persiano, M. Yung. On Monotone Formula Closure of SZK. 35th FOCS, IEEE, pp. 454\u2013465, 1994.","DOI":"10.1109\/SFCS.1994.365745"},{"issue":"3","key":"8_CR35","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/BF00196725","volume":"4","author":"C. P. Schnorr","year":"1991","unstructured":"C. P. Schnorr. Efficient signature generation for smart cards. Journal of Cryptology, 4(3):239\u2013252, 1991.","journal-title":"Journal of Cryptology"},{"issue":"1","key":"8_CR36","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1137\/0206006","volume":"6","author":"R. Solovay","year":"1977","unstructured":"R. Solovay and V. Strassen. A fast monte-carlo test for primality. SIAM Journal on Computing, 6(1):84\u201385, Mar. 1977.","journal-title":"SIAM Journal on Computing"},{"key":"8_CR37","doi-asserted-by":"crossref","unstructured":"J. van de Graaf and R. Peralta. A simple and secure way to show the validity of your public key. In Advances in Cryptology \u2014 CRYPTO\u2019 87, volume 293 of LNCS, pp. 128\u2013134. Springer-Verlag, 1988.","DOI":"10.1007\/3-540-48184-2_9"},{"issue":"159","key":"8_CR38","doi-asserted-by":"publisher","first-page":"225","DOI":"10.2307\/2007633","volume":"39","author":"H. C. Williams","year":"1982","unstructured":"H. C. Williams. A p + 1 method of factoring. Mathematics of Computation, 39(159):225\u2013234, 1982.","journal-title":"Mathematics of Computation"},{"key":"8_CR39","unstructured":"X9.31-1998 Digital Signatures using reversible public key cryptography for the financial services industry (rDSA). American National Standard, Working Draft, 59 pages, 1998."}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2014 EUROCRYPT \u201999"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/3-540-48910-X_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,21]],"date-time":"2025-01-21T14:47:22Z","timestamp":1737470842000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/3-540-48910-X_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1999]]},"ISBN":["9783540658894","9783540489108"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/3-540-48910-x_8","relation":{},"ISSN":["0302-9743"],"issn-type":[{"value":"0302-9743","type":"print"}],"subject":[],"published":{"date-parts":[[1999]]}}}