{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,10,4]],"date-time":"2026-10-04T20:59:16Z","timestamp":1791147556280,"version":"4.1.0"},"reference-count":29,"publisher":"Society for Industrial & Applied Mathematics (SIAM)","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["SIAM J. Comput."],"published-print":{"date-parts":[[1986,5]]},"abstract":"<jats:p>Two closely-related pseudo-random sequence generators are presented: The ${1 \/ P}$generator, with input P a prime, outputs the quotient digits obtained on dividing 1 by P. The $x^2 \\bmod N$generator with inputs N, $x_0 $ (where $N = P \\cdot Q$ is a product of distinct primes, each congruent to 3 mod 4, and $x_0 $ is a quadratic residue $\\bmod N$), outputs $b_0 b_1 b_2 \\cdots $ where $b_i = {\\operatorname{parity}}(x_i )$ and $x_{i + 1} = x_i^2 \\bmod N$.<\/jats:p>\n                  <jats:p>From short seeds each generator efficiently produces long well-distributed sequences. Moreover, both generators have computationally hard problems at their core. The first generator\u2019s sequences, however, are completely predictable (from any small segment of $2|P| + 1$ consecutive digits one can infer the \u201cseed,\u201d P, and continue the sequence backwards and forwards), whereas the second, under a certain intractability assumption, is unpredictable in a precise sense. The second generator has additional interesting properties: from knowledge of $x_0 $ and N but notP or Q, one can generate the sequence forwards, but, under the above-mentioned intractability assumption, one can not generate the sequence backwards. From the additional knowledge of P and Q, one can generate the sequence backwards; one can even \u201cjump\u201d about from any point in the sequence to any other. Because of these properties, the $x^2 \\bmod N$generator promises many interesting applications, e.g., to public-key cryptography. To use these generators in practice, an analysis is needed of various properties of these sequences such as their periods. This analysis is begun here.<\/jats:p>","DOI":"10.1137\/0215025","type":"journal-article","created":{"date-parts":[[2005,2,24]],"date-time":"2005-02-24T06:28:10Z","timestamp":1109226490000},"page":"364-383","source":"Crossref","is-referenced-by-count":706,"title":["A Simple Unpredictable Pseudo-Random Number Generator"],"prefix":"10.1137","volume":"15","author":[{"given":"L.","family":"Blum","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M.","family":"Blum","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M.","family":"Shub","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"351","published-online":{"date-parts":[[2006,7,13]]},"reference":[{"key":"R1","doi-asserted-by":"crossref","unstructured":"L. Adleman,  On distinguishing prime numbers from composite numbers,  Proc. 21st IEEE Symposium on Foundations of Computer Science,  1980,  387\u2013408","DOI":"10.1109\/SFCS.1980.28"},{"key":"R2","unstructured":"E. Bach,  How to generate random integers with known factorization, submitted for publication"},{"key":"R3","volume-title":"Ergodic theory and information","author":"Billingsley Patrick","year":"1965"},{"key":"R4","unstructured":"M. Blum,  Coin flipping by telephone,  Proc. IEEE Spring COMPCON,  1982,  133\u2013137"},{"key":"R5","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.72"},{"key":"R6","doi-asserted-by":"crossref","unstructured":"G. Brassard,  D.  Chaum, R. L. Rivest, A. T. Sherman,  On computationally secure authentication tags requiring short secret shared keys,  Advances in Cryptology, Proc. of Crypto 82, Plenum Press, New York,  1983,  79\u201386","DOI":"10.1007\/978-1-4757-0602-4_7"},{"key":"R7","volume-title":"History of the Theory of Numbers","author":"Dickson L.","year":"1919"},{"key":"R8","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"R9","volume-title":"Graph algorithms","author":"Even Shimon","year":"1979"},{"key":"R10","volume-title":"Disquisitiones arithmeticae","author":"Gauss Carl G.","year":"1966"},{"key":"R11","doi-asserted-by":"crossref","unstructured":"S. Goldwasser, S. Micali,  Probabilistic encryption and how to play mental poker keeping secret all partial information,  14th STOC,  1982,  365\u2013377","DOI":"10.1145\/800070.802212"},{"key":"R12","volume-title":"Shift Register Sequences","author":"Golomb S.","year":"1982"},{"key":"R13","volume-title":"Formal languages and their relation to automata","author":"Hopcroft John","year":"1969"},{"key":"R14","first-page":"405","volume":"71","author":"Kac Mark","year":"1983","journal-title":"Amer. Sci."},{"key":"R15","volume-title":"The art of computer programming. Vol. 2","author":"Knuth Donald","year":"1981"},{"key":"R16","volume-title":"Fundamentals of number theory","author":"LeVeque William J.","year":"1977"},{"key":"R17","unstructured":"R. Lipton,  How to cheat at mental poker, preliminary report, Univ. California, Berkeley,  1979, August"},{"key":"R18","doi-asserted-by":"crossref","unstructured":"G. Miller, Ph.D. Thesis,  Riemann's hypothesis and tests for primality, Univ. California, Berkeley,  1975","DOI":"10.1145\/800116.803773"},{"key":"R19","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.73"},{"key":"R20","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1978.1055817"},{"key":"R21","unstructured":"M. O. Rabin,  Digital signatures and public-key functions as intractable as factorization, Tech. memo, MIT\/LCS\/TR-212, Massachusetts Institute of Technology,  1979"},{"key":"R22","doi-asserted-by":"publisher","DOI":"10.1016\/0022-314X(80)90084-0"},{"key":"R23","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"R24","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4684-6686-7_5"},{"key":"R25","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-10843-2_43"},{"key":"R26","volume-title":"Solved and unsolved problems in number theory","author":"Shanks Daniel","year":"1978"},{"key":"R27","doi-asserted-by":"publisher","DOI":"10.1137\/0206006"},{"key":"R28","first-page":"768","volume-title":"Collected Works","volume":"5","author":"von Neumann J.","year":"1963"},{"key":"R29","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.45"}],"container-title":["SIAM Journal on Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/epubs.siam.org\/doi\/pdf\/10.1137\/0215025","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,21]],"date-time":"2026-08-21T18:37:46Z","timestamp":1787337466000},"score":1,"resource":{"primary":{"URL":"https:\/\/epubs.siam.org\/doi\/10.1137\/0215025"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1986,5]]},"references-count":29,"journal-issue":{"issue":"2","published-print":{"date-parts":[[1986,5]]}},"alternative-id":["10.1137\/0215025"],"URL":"https:\/\/doi.org\/10.1137\/0215025","relation":{},"ISSN":["0097-5397","1095-7111"],"issn-type":[{"value":"0097-5397","type":"print"},{"value":"1095-7111","type":"electronic"}],"subject":[],"published":{"date-parts":[[1986,5]]}}}