The authors show that the use of four-prime RSA moduli with prespecifi
ed bits proposed by Vanstone and Zuccherato may have a certain securit
y problem. A possible way to avoid this problem is described. A more r
obust method for structuring RSA moduli which gives almost random modu
li is also proposed.