inversion''problems. Our main result is that two problems in this class, which we call the
chosen-target and known-target inversion problems, respectively, have polynomially
equivalent computational complexity. We show how this leads to a proof of security for
Chaum's RSA-based blind signature scheme in the random oracle model based on the
assumed hardness of either of these problems. We define and prove analogous results …