pq = N p,q为两个质数
记[N,e], [N,d]分别为算法中的公钥和私钥,根据算法性质知ed = 1 mod (p-1)(q-1) 这里的等号为模等,下同
则ed=1 mod (p-1) ed=1 mod (q-1)
记n为明文,则n^e=c mod N, c为密文
设ed = a(p-1) + 1 a > 1
则解密过程c^d = n^e^d = n^(ed) = n^[a(p-1)+1]=n*n^[a(p-1)]
因p为质数,根据欧拉定理有n^(p-1) = 1 mod p
故n^[a(p-1)] = 1 mod p
n*n^[a(p-1)] = n mod p, 即c^d = n mod p
同理可证c^d = n mod q
因为p,q都为质数, 所以 c^d = n mod pq, 即 c^d = n mod N
解密过程得证