Optionally, quadratic residue group QRN of random number space Z*N is an internal direct product of group QRNα and group QRNβ, QRNβ=α, the predetermined cyclic group is an internal direct product of group QRNβ and group ?1
, group
?1
is a second-order cyclic group generated by element (?1 mod N) in random number space Z*N, and a=1/2.
Optionally, when N=P·Q, P and Q are prime numbers with a length of n/2 bits, P≡Q≡3 mod 4, and gcd(P?1, Q?1)=2, it is satisfied that α=pq, β=(P?1)(Q?1)/(4pq), gcd(α, β)=1, p|(P?1), q|(Q?1), and p and q are prime numbers with a length of i/2 bits.
Optionally, h=?y2β mod N, where y belongs to random number space Z*N.
Optionally, n=2048, and 224≤i<n.