135 lines
4.6 KiB
Markdown
135 lines
4.6 KiB
Markdown
# Elgamal Encryption
|
||
|
||
#### Extending Diffie-Hellmen to Encryption
|
||
|
||
We could do is multiply the plain text by the key generated
|
||
|
||
$y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
|
||
|
||
### Elgamal
|
||
|
||
- Because this is public key encryption, we can make some efficiency savings by not sending all the information both ways every time
|
||
- If encryption is from Alice to Bob, Bob only needs to publish a public key once
|
||
- The scheme provides some other security benefits - **ephemeral keys**
|
||
|
||
#### Elgamal Key Generation
|
||
|
||
**Bob**:
|
||
|
||
1. Choose large prime $p$
|
||
2. Choose primitive element $g\in\mathbb{Z}^*_p$ or in a subgroup of $\mathbb{Z}^*_p$
|
||
3. Choose $k_{pr}=b\in\{1,2,...,p-1\}$
|
||
4. Compute $B \equiv g^b\mod p$
|
||
5. Publish public key $k_{pub}=(p,g,B)$
|
||
|
||
#### Elgamal Key Generation
|
||
|
||
**Alice**:
|
||
|
||
1. Choose $a\in \{1,2,...,p-1\}$
|
||
2. Compute ephemeral key
|
||
- $k_E\equiv g^a\mod p$
|
||
- Remember ephemeral means the key is generated every time communication happens
|
||
3. Compute masking key
|
||
- $k_M\equiv B^a\mod p$
|
||
4. Encrypt message $x\in\mathbb{Z}^*_p$
|
||
- $y\equiv x\cdot k_M\mod p$
|
||
5. Send $(k_E,y)$
|
||
|
||
#### Elgamal Decryption
|
||
|
||
1. Compute masking key
|
||
- $k_M\equiv k_E^b\mod p$
|
||
2. Decrypt message
|
||
- $x\equiv y\cdot k_M^{-1}\mod p$
|
||
|
||
### Computational Efficiency
|
||
|
||
To calculate bobs private key we use one exponentiation
|
||
|
||
Alice has to do two binary exponentiation to send a message to bob
|
||
|
||

|
||
|
||
- Both the exponentiations during encryption can be pre-computed during down time
|
||
- We can also improve on the decryption step using Fermat’s little theorem
|
||
- Fermat’s Little Theorem: $a^{p-1}\equiv 1\mod p$
|
||
1. Compute $k_M=k_E^b\mod 67$
|
||
2. Compute $k_M^{-1}$
|
||
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
|
||
|
||
#### Practicalities
|
||
|
||
- Elgamal is a probabilistic encryption scheme. It uses an ephemeral key pair $a$ and $k_E=g^a\mod p$
|
||
- Elgamal has a major weakness if you reuse an ephemeral key, and is also less efficient than simply using Diffie-Hellman than AES
|
||
- The other form of Elgamal is a scheme for digital signatures, variants of which are much more popular
|
||
|
||
### Elgamal Digital Signature
|
||
|
||
**Bob**:
|
||
|
||
1. Choose $g,p$
|
||
2. Choose $k_{pr}=b\in\{1,2,...,p-1\}$
|
||
3. Compute $k_{pub}=B\equiv g^b\mod p$
|
||
4. Publish public key $k_{pub}=(p,g,B)$
|
||
|
||
Then decide the ephemeral key $k\in\{1,2,...,p-2\}$ where $\gcd(k,p-1)=1$
|
||
|
||
- $r\equiv g^k\mod p$
|
||
- $s\equiv(m-b\cdot r)\cdot k^{-1}\mod p-1$
|
||
|
||
Bob sends the message, and $r$ and $s$
|
||
|
||
Alice to verify:
|
||
|
||
- $ver_{k_{pub}}(m,(r,s) =\\ g^m = B^rr^s\mod p$
|
||
|
||
#### Proof
|
||
|
||
Signature: $s=(m-b\cdot r)\cdot k^{-1}\mod p-1$
|
||
|
||
- $\therefore s\cdot k=x-b\cdot r \mod p-1$
|
||
- $\therefore x=b\cdot r+k\cdot s \mod p-1$
|
||
|
||
Then
|
||
|
||
- $g^x\equiv B^rr^s\equiv(g^b)^r(g^k)^s \mod p$
|
||
- $g^x\equiv g^{br}\cdot g^{ks}$
|
||
- $\therefore g^x\equiv g^{b\cdot r + k\cdot s}\mod p$
|
||
|
||
Recall: $a^{p-1}\equiv 1\mod p$ for some $m$
|
||
|
||
- $a^m\equiv a^{q\cdot(p-1)+r}\mod p$
|
||
- $\therefore a^m\equiv (a^q)^{(p-1)}\cdot a^r\mod p$
|
||
- $\therefore a^m\equiv 1\cdot a^r\mod p$
|
||
- So $a^m\equiv a^{m \mod p-1}\mod p$
|
||
|
||
> If exponents are equal $\mod p-1$, then terms are equal $\mod p$
|
||
|
||
#### Practicalities
|
||
|
||
- As with RSA it’s customary to hash the message and use $H(m)$ not $m$
|
||
- The combined message and signature $m, (r,s)$ is roughly 3 times the size of the prime $p$, which makes Elgamal signatures quite inefficient
|
||
- Note that the signature $s\equiv (m-b\cdot r)\cdot k^{-1}\mod p-1$ is calculated in a prime order subgroup of $\mathbb{Z}_p^*$
|
||
- Without hashing Elgamal is vulnerable to existential forgeries, and key recovery is possible if you reuse the ephemeral key $k$
|
||
|
||
### DSA
|
||
|
||
- Based on Elgamal, DSA was developed by NIST as an alternative to RSA
|
||
- Computed in a subgroup of prime order q, which is usually 160 bits
|
||
- This means the signature (r, s) is 320 bits
|
||
- Hashing is enforced by the algorithm, and a hash function must match the key size
|
||
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
|
||
- Index calculus does not apply to the sub-group, so 160 bit DSA has a security of 80 bits
|
||
- In practice larger keys would be required now
|
||
|
||
#### ECDSA
|
||
|
||
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
|
||
- More efficient, does not require modulus of thousands of bits
|
||
- Security level is based on generic attacks against EC
|
||
- i.e $\sqrt{|\#q|}$
|
||
- Deterministic generation of $k$ is often used for safety (RFC 6979)
|
||
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
|
||
- This is because reusing the ephemeral key is bad news
|
||
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist |