This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+22 -22
View File
@@ -1,8 +1,8 @@
# Elgamal Encryption
#### Extending Diffie-Hellmen to Encryption
#### Extending Diffie-Hellman to Encryption
We could do is multiply the plain text by the key generated
What we could do is multiply the plain text by the key generated
$y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
@@ -28,35 +28,35 @@ $y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
1. Choose $a\in \{1,2,...,p-1\}$
2. Compute ephemeral key
- $k_E\equiv g^a\mod p$
- Remember ephemeral means the key is generated every time communication happens
- $k_E\equiv g^a\mod p$
- Remember ephemeral means the key is generated every time communication happens
3. Compute masking key
- $k_M\equiv B^a\mod p$
- $k_M\equiv B^a\mod p$
4. Encrypt message $x\in\mathbb{Z}^*_p$
- $y\equiv x\cdot k_M\mod p$
- $y\equiv x\cdot k_M\mod p$
5. Send $(k_E,y)$
#### Elgamal Decryption
1. Compute masking key
- $k_M\equiv k_E^b\mod p$
- $k_M\equiv k_E^b\mod p$
2. Decrypt message
- $x\equiv y\cdot k_M^{-1}\mod p$
- $x\equiv y\cdot k_M^{-1}\mod p$
### Computational Efficiency
To calculate bobs private key we use one exponentiation
To calculate Bob's private key we use one exponentiation
Alice has to do two binary exponentiation to send a message to bob
Alice has to do two binary exponentiations to send a message to Bob
![1648752755.png](img/1648752755.png)
- Both the exponentiations during encryption can be pre-computed during down time
- Both the exponentiations during encryption can be pre-computed during downtime
- We can also improve on the decryption step using Fermat’s little theorem
- Fermat’s Little Theorem: $a^{p-1}\equiv 1\mod p$
1. Compute $k_M=k_E^b\mod 67$
2. Compute $k_M^{-1}$
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
1. Compute $k_M=k_E^b\mod 67$
2. Compute $k_M^{-1}$
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
#### Practicalities
@@ -119,17 +119,17 @@ Recall: $a^{p-1}\equiv 1\mod p$ for some $m$
- Computed in a subgroup of prime order q, which is usually 160 bits
- This means the signature (r, s) is 320 bits
- Hashing is enforced by the algorithm, and a hash function must match the key size
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
- Index calculus does not apply to the sub-group, so 160 bit DSA has a security of 80 bits
- In practice larger keys would be required now
- In practice larger keys would be required now
#### ECDSA
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
- More efficient, does not require modulus of thousands of bits
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
- More efficient, does not require modulus of thousands of bits
- Security level is based on generic attacks against EC
- i.e $\sqrt{|\#q|}$
- i.e. $\sqrt{|\#q|}$
- Deterministic generation of $k$ is often used for safety (RFC 6979)
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
- This is because reusing the ephemeral key is bad news
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
- This is because reusing the ephemeral key is bad news
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist