why QR_n in Cramer-Shoup's signature scheme?

From: #ZHOU SUJING# (zhousujing_at_pmail.ntu.edu.sg)
Date: 11/26/03


Date: Wed, 26 Nov 2003 10:03:16 +0800

In the singature scheme based on strong RSA, the public parameters are
chosen from QR_n,
is it necessary ? The proof seems not too much dependent on that
condition. Only because a large
cyclic group is needed? If so, any other cyclic group in Z^*_n will do,
not nessecarily QR_n. Right?