## Calculating with and

Calculating with and without p,q (10) squares and roots mod n using p,q (usable as secret operations) • testing whether square is simple (n = p •q, p,q prime, p�q) x � QR n � x � QR p � x � QR q Chinese Remainder Theorem proof: “�” x � w 2 mod n � x � w 2 mod p � x � w 2 mod q “�” x � w p 2 mod p � x � wq 2 mod q w := CRA(w p,w q) then w � w p mod p � w � w q mod q using the Chinese Remainder Theorem for w 2 � w p 2 � x mod p � w 2 � wq 2 � x mod q we have w 2 � x mod n 177

Calculating with and without p,q (11) Continuation squares und roots mod n using p,q x � QR n � x has exactly 4 roots (mod p and mod q : ± w p, ± w q. therefore the 4 combinations according to the Chinese Remainder Theorem) • extracting a root is easy (p, q � 3 mod 4) determine roots wp, wq mod p, q w p : � x p�1 4 combine using CRA w q : � x q�1 4 178

