An Indexing for Quadratic Residues Modulo and a Non-uniform Efficient Decoding Algorithm
arXiv:1805.04731
Abstract
An \emph{indexing} of a finite set is a bijection . We present an indexing for the set of quadratic residues modulo that is decodable in polynomial time on the size of , given the factorization of . One consequence of this result is a procedure for sampling quadratic residues modulo , when the factorization of is known, that runs in strict polynomial time and requires the theoretical minimum amount of random bits (i.e., bits, where is Euler's totient function and is the number of distinct prime factors of ). A previously known procedure for this same problem runs in expected (not strict) polynomial time and requires more random bits.