# The Rabin Cryptosystem & analysis in measure of Chinese

Michael Rabin discovered what I like to call a version of RSA, although it is more properly regarded as a public key cryptosystem in its own right. A public-key cryptosystem based on squaring modulo the product of two primes, introduced in 1979 by Michael O. Rabin. In 1979, Rabin invented the Rabin cryptosystem, the first asymmetric cryptosystem whose security was proved equivalent to the intractability of integer factorization. In Rabin scheme, public key is an integer n. Figure 10.2 General idea of asymmetric-key cryptosystem. Unlike in symmetric-key cryptography, plaintext and ciphertext are treated as integers in asymmetric-key cryptography. The Rabin cryptosystem was the first asymmetric cryptosystem where recovering the entire plaintext from the ciphertext could be proven to be as hard as factoring. Rabin-like cryptosystem (except Rabin-Williams scheme) involves a process that depends heavily on the CRT or Garner's algorithm (i.e. the process to recover all the modulo square roots). In distributed cryptosystem a secret key is distributed among the participants of the system, in the way that only a group of some authorized users can perform any actions related to the secret key. Rabin Cryptosystem is a variant of the RSA Cryptosystem. It has the advantage over RSA that finding the private and forgery key are both as hard as factoring.

The Rabin scheme used in public-key cryptosystem is here revisited with a focus limited to a few specific open issues. The primes p and q are the private key. Choose to simplify the computation of square roots modulo p and q. The Rabin Cryptosystem: B encrypts a message m and sends the ciphertext. Rabin cryptosystem has security reducible to the hardness of integer factorization. However the Rabin cryptosystem has the advantage that the problem on which it relies has been proved to be as hard as integer factorization. For encryption, Rabin Cryptosystem is more efficient than RSA. We have extended the domain of primes in Rabin cryptosystem to a subset of the primes satisfying certain conditions. Rabin cryptosystem will be more applicable and flexible if we include a wide range of primes.

The Rabin cryptosystem with the Williams padding is sometimes called the Rabin-Williams cryptosystem. RABIN SIGNATURE SCHEME: The Rabin signature scheme is a variant of the RSA signature scheme. Rabin's cryptosystem is based on two integers p and q each congruent to 3 modulo 4 which form the private key; their product, n = p × q, is the public key. Then to encrypt the message m. Rabin cryptosystem has the disadvantage that each output of the Rabin function can be generated by any of four possible inputs; if each output is a ciphertext, extra complexity is required on decryption to identify which of the four possible inputs was the true plaintext. The Rabin Cryptosystem was first of a provably secure public key cryptosystem where the problem faced by an attacker is of recovering plaintext from some given cipher text is computationally equivalent to factoring. A desirable property of any cryptosystem is a proof that breaking it is as difficult as solving a computational problem that is widely believed to be hard. Security of the Rabin Cryptosystem: Since the decryption function of the Rabin cryptosystem is based on computing square roots modulo N, there exist four square roots of c mod n (c = m2 mod n). This H-Rabin cryptosystem is a public key cryptosystem where the private key is composed of three primes, p, q and r and a public key composed of n = p. q. r and it is based on the hardness of factorization. Key generation: As with all asymmetric cryptosystems, the Rabin system uses both a public and a private key. Rabin cryptosystem: An integer a in Z_n is called a quadratic residue modulo n if there exists an integer b such that b^2 ≡ a (mod n). Otherwise a is called a quadratic nonresidue modulo n. The Rabin public-key cryptosystem is revisited with a focus on the problem of identifying the encrypted message unambiguously for any pair of primes. The Rabin signature is also reconsidered and a deterministic padding mechanism is proposed. In particular, message decryption requires one out of four roots of a quadratic equation in a residue ring to be chosen, and a longstanding problem is to identify unambiguously and deterministically the encrypted message.

