Files
notes/docs/lectures/cryptography/13_elgamal.md
T

135 lines
4.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Elgamal Encryption
#### Extending Diffie-Hellmen to Encryption
We could do is multiply the plain text by the key generated
$y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
### Elgamal
- Because this is public key encryption, we can make some efficiency savings by not sending all the information both ways every time
- If encryption is from Alice to Bob, Bob only needs to publish a public key once
- The scheme provides some other security benefits - **ephemeral keys**
#### Elgamal Key Generation
**Bob**:
1. Choose large prime $p$
2. Choose primitive element $g\in\mathbb{Z}^*_p$ or in a subgroup of $\mathbb{Z}^*_p$
3. Choose $k_{pr}=b\in\{1,2,...,p-1\}$
4. Compute $B \equiv g^b\mod p$
5. Publish public key $k_{pub}=(p,g,B)$
#### Elgamal Key Generation
**Alice**:
1. Choose $a\in \{1,2,...,p-1\}$
2. Compute ephemeral key
- $k_E\equiv g^a\mod p$
- Remember ephemeral means the key is generated every time communication happens
3. Compute masking key
- $k_M\equiv B^a\mod p$
4. Encrypt message $x\in\mathbb{Z}^*_p$
- $y\equiv x\cdot k_M\mod p$
5. Send $(k_E,y)$
#### Elgamal Decryption
1. Compute masking key
- $k_M\equiv k_E^b\mod p$
2. Decrypt message
- $x\equiv y\cdot k_M^{-1}\mod p$
### Computational Efficiency
To calculate bobs private key we use one exponentiation
Alice has to do two binary exponentiation to send a message to bob
![1648752755.png](img/1648752755.png)
- Both the exponentiations during encryption can be pre-computed during down time
- We can also improve on the decryption step using Fermat’s little theorem
- Fermat’s Little Theorem: $a^{p-1}\equiv 1\mod p$
1. Compute $k_M=k_E^b\mod 67$
2. Compute $k_M^{-1}$
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
#### Practicalities
- Elgamal is a probabilistic encryption scheme. It uses an ephemeral key pair $a$ and $k_E=g^a\mod p$
- Elgamal has a major weakness if you reuse an ephemeral key, and is also less efficient than simply using Diffie-Hellman than AES
- The other form of Elgamal is a scheme for digital signatures, variants of which are much more popular
### Elgamal Digital Signature
**Bob**:
1. Choose $g,p$
2. Choose $k_{pr}=b\in\{1,2,...,p-1\}$
3. Compute $k_{pub}=B\equiv g^b\mod p$
4. Publish public key $k_{pub}=(p,g,B)$
Then decide the ephemeral key $k\in\{1,2,...,p-2\}$ where $\gcd(k,p-1)=1$
- $r\equiv g^k\mod p$
- $s\equiv(m-b\cdot r)\cdot k^{-1}\mod p-1$
Bob sends the message, and $r$ and $s$
Alice to verify:
- $ver_{k_{pub}}(m,(r,s) =\\ g^m = B^rr^s\mod p$
#### Proof
Signature: $s=(m-b\cdot r)\cdot k^{-1}\mod p-1$
- $\therefore s\cdot k=x-b\cdot r \mod p-1$
- $\therefore x=b\cdot r+k\cdot s \mod p-1$
Then
- $g^x\equiv B^rr^s\equiv(g^b)^r(g^k)^s \mod p$
- $g^x\equiv g^{br}\cdot g^{ks}$
- $\therefore g^x\equiv g^{b\cdot r + k\cdot s}\mod p$
Recall: $a^{p-1}\equiv 1\mod p$ for some $m$
- $a^m\equiv a^{q\cdot(p-1)+r}\mod p$
- $\therefore a^m\equiv (a^q)^{(p-1)}\cdot a^r\mod p$
- $\therefore a^m\equiv 1\cdot a^r\mod p$
- So $a^m\equiv a^{m \mod p-1}\mod p$
> If exponents are equal $\mod p-1$, then terms are equal $\mod p$
#### Practicalities
- As with RSA it’s customary to hash the message and use $H(m)$ not $m$
- The combined message and signature $m, (r,s)$ is roughly 3 times the size of the prime $p$, which makes Elgamal signatures quite inefficient
- Note that the signature $s\equiv (m-b\cdot r)\cdot k^{-1}\mod p-1$ is calculated in a prime order subgroup of $\mathbb{Z}_p^*$
- Without hashing Elgamal is vulnerable to existential forgeries, and key recovery is possible if you reuse the ephemeral key $k$
### DSA
- Based on Elgamal, DSA was developed by NIST as an alternative to RSA
- Computed in a subgroup of prime order q, which is usually 160 bits
- This means the signature (r, s) is 320 bits
- Hashing is enforced by the algorithm, and a hash function must match the key size
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
- Index calculus does not apply to the sub-group, so 160 bit DSA has a security of 80 bits
- In practice larger keys would be required now
#### ECDSA
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
- More efficient, does not require modulus of thousands of bits
- Security level is based on generic attacks against EC
- i.e $\sqrt{|\#q|}$
- Deterministic generation of $k$ is often used for safety (RFC 6979)
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
- This is because reusing the ephemeral key is bad news
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist