As described above, generator h of selected predetermined cyclic group QRNβ??1
 can be represented as h=?y2β mod N, where y∈Z*N. The size of predetermined cyclic group QRNβ?
?1
 is 2α, and therefore the elements included in predetermined cyclic group QRNβ?
?1
 are {h0, h1, h2, . . . , h2α?1}. In a subsequent encryption process, random number r needs to be selected, so that hr belongs to predetermined cyclic group QRNβ?
?1
. Therefore, a value of random number r belongs to [0, 2α?1], in other words, a length of random number r is related to a length of α.