摘要 |
The invention relates to a method of determining a plaintext M on the basis of a cipher C and using a secret key d, wherein the secret key d is used in binary form, wherein the plaintext M is determined in each iteration step i for the corresponding bit d<SUB>i</SUB> and a security variable M<SUB>n</SUB> is determined in parallel therewith, and then a verification variable x is determined by means of a bit-compatible exponent of the secret key d. |