Hardness of structured totient preimage reconstruction in growing parameter regimes

Establish whether the Structured Totient Preimage search relation is computationally hard in a growing parameter regime, particularly when the number k of distinct λ-bit primes grows with λ and the public shifted product is supplied in factored form.

Background

The paper distinguishes general inverse-totient computation from STP, where the hidden witness consists of exactly k distinct λ-bit primes and the public value is the product of their shifted factors. It notes that the resemblance to Product Partition does not itself yield a hardness reduction because prime exponents may be split among candidate factors and each completed factor must be one less than a prime.

A polynomial-time factored-input regime is ruled out when k is fixed and Ω(x)=O(log λ). The unresolved issue is whether hardness can arise for an explicitly growing parameter family outside that tractable regime; this question is also central to the proposed Structured Totient Preimage Assumption and its cryptographic use.

References

Whether the restricted search relation is hard in a growing parameter regime remains open.

The Structured Totient Preimage Problem: Reconstruction, Collisions, and Cryptographic Implications  (2608.19191 - Lizama-Pérez, 19 Aug 2026) in Section 6, Relation to inverse-totient complexity