To this end, it will be assumed in the description that Gq is the unique subgroup of order q of p *, where, p is a prime such that q divides p-1, and p-1 also contains another prime factor of size comparable to the size of a q (such as to prevent efficient factorization of p-1).