Question: Problem 6 . 2 You learned that the ElGamal scheme is not IND - CCA secure , so consider the following variant of the scheme.
Problem
You learned that the ElGamal scheme is not INDCCA secure so consider the following variant of
the scheme.
Let and be large primes such that divides Let be the order subgroup generated by
ginG. Assume that the DDH assumption holds in Consider the following scheme
defined with Message space and ciphertext space :
Algorithm
Algorithm Algorithm
MlarrW
Return WlarrK return
Return
Show that is still not secure under INDCCA even if DDH is hard for Remember that
adversaries know the public parameters
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
