Assume we have a large prime

  • can be computed efficiently
  • however, given , it is difficult to find

Example

and are public parameters (known by everyone) It is difficult to find using and