we may transform S so that

with e1, em+1 =0,1,2or3 and ai = 1 or 2 for i = 1,..., m and m > 0. Multiplying by a suitable power of X we obtain

with m > 0 and a =0,1,2 or 3. Assume that m > 1 and let

We show by induction that

or

This claim ...
Get A Course in Mathematical Cryptography now with the O’Reilly learning platform.
O’Reilly members experience live online training, plus books, videos, and digital content from nearly 200 publishers.