we may transform S so that

image

with e1, em+1 =0,1,2or3 and ai = 1 or 2 for i = 1,..., m and m > 0. Multiplying by a suitable power of X we obtain

image

with m > 0 and a =0,1,2 or 3. Assume that m > 1 and let

image

We show by induction that

image

or

image

This claim ...

Get A Course in Mathematical Cryptography now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.