
### Problem 1

- 2 points. Correctly construct the quantity (e.g. $s = \frac{c_1^{e_2}}{c_2^{e_1}} \bmod N$) that can be used to distinguish the two ciphertexts.
- *1 point. Correctly choose two different messages $m_0, m_1$ (such as $m_0 = 1, m_1 = 2$ or $m_0 = 1, m_1 = -1$ or something else) and correctly compute the distinguish quantity when these messages are encrypted under the new RSA-PKE scheme.
- *1 point. Show that the quantity of two different messages are distinct.
- 1 point. Give a conclusion on why these processes can be used to break the Chosen-Plaintext security.