arXiv · 1509.01504
Insecure primitive elements in an ElGamal signature protocol
Abstract
Consider the classical ElGamal digital signature scheme based on the modular relation $\alpha^m\equiv y^r\, r^s\ [p]$. In this work, we prove that if we can compute a natural integer $i$ such that $\alpha^i\ mod\ p$ is smooth and divides $p-1$, then it is possible to sign any given document without knowing the secret key. Therefore we extend and reinforce Bleichenbacher's attack presented at Eurocrypt'96.
Explore related subjects
Keep this discovery
Omar Khadir. 2015-09-04. Insecure primitive elements in an ElGamal signature protocol. https://arxiv.org/abs/1509.01504
Cite the original work for its findings. Save a collection to share your selection of sources.