title = "Collision in the DSA Function",

abstract = "We study possible collisions among the values of the DSA function f(s) = (g(s) rem p) rem t where g is order t modulo a prime p and n rem k denotes the remainder of n on division by k. In particular, in a certain range of p and t we guarantee the existence of collisions and also give a nontrivial algorithm for inverting this function.",

