Strong RSA ⇒ COM

Strong RSA implies COM.

Statement

Migrated verbatim from rsa-assumption § Strong RSA:

The strong RSA assumption strengthens the standard assumption by allowing the adversary to choose the exponent itself (subject to ). Formally, the adversary outputs a pair with and . This is used in constructions of signature schemes and commitments with stronger security guarantees.

Notes

source: folklore: the claim carried no citation on the page it was migrated from, and none was invented.

class: unstated: no citing page says which notion of reduction is meant. Recording a class the wiki does not state would add a claim.

Recorded during migration and not fixed — these are claims about the source text, not changes to it:

  • No citation.
  • content/Primitives/commitment-scheme.md exists but “commitments” is left as plain text with no wikilink.