The Polynomial Composition Problem in (ℤ/nℤ)[X]

  • Marc Joye
  • David Naccache
  • Stéphanie Porte
Part of the Lecture Notes in Computer Science book series (LNCS, volume 6035)


Let n be an RSA modulus and let \(\mathcal {P},\mathcal{Q} \in (\mathbb{Z}/n\mathbb{Z})[X]\). This paper explores the following problem: Given polynomials \(\mathcal{Q}\) and \(\mathcal{Q}(\mathcal{P})\), find polynomial \(\mathcal{P}\). We shed light on the connections between the above problem and the RSA problem and derive from it new zero-knowledge protocols suited to smart-card applications.


Polynomial composition zero-knowledge protocols Fiat-Shamir protocol Guillou-Quisquater protocol smart cards 


  1. 1.
    Cohen, H.: A Course in Computational Algebraic Number Theory. In: GTM 138. Springer, Heidelberg (1993)Google Scholar
  2. 2.
    Coppersmith, D., Franklin, M., Patarin, J., Reiter, M.: Low-exponent RSA with related messages. In: Maurer, U.M. (ed.) EUROCRYPT 1996. LNCS, vol. 1070, pp. 1–9. Springer, Heidelberg (1996)Google Scholar
  3. 3.
    Fiat, A., Shamir, A.: How to prove yourself: Practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO 1986. LNCS, vol. 263, pp. 186–194. Springer, Heidelberg (1987)Google Scholar
  4. 4.
    Guillou, L.C., Quisquater, J.-J.: A practical zero-knowledge protocol fitted to security microprocessor minimizing both transmission and memory. In: Günther, C.G. (ed.) EUROCRYPT 1988. LNCS, vol. 330, pp. 123–128. Springer, Heidelberg (1988)Google Scholar
  5. 5.
    Menezes, A.J., van Oorschot, P.C., Vanstone, S.A.: Handbook of Applied Cryptography. CRC Press, Boca Raton (1997)zbMATHGoogle Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2010

Authors and Affiliations

  • Marc Joye
    • 1
  • David Naccache
    • 2
  • Stéphanie Porte
    • 3
  1. 1.Thomson R&D, Security Competence CenterCesson-Sévigné CedexFrance
  2. 2.Ecole normale supérieureDépartement d’informatiqueParis Cedex 05France
  3. 3.Smart ConsultingLa CiotatFrance

Personalised recommendations