Pierre-Alain Fouque, David Pointcheval, Jacques Stern, and Sbastien Zimmer, Hardness of distinguishing the MSB or LSB of secret keys in Diffie-Hellman schemes, In Michele Bugliesi, Bart Preneel, Vladimiro Sassone, and Ingo Wegener, editors, Automata, Languages and Programming, volume 4052 of Lecture Notes in Computer Science, pages 240–251. Springer Berlin Heidelberg, 2006.