Question: Problem 6 . 2 You learned that the ElGamal scheme is not IND - CCA secure , so consider the following variant of the scheme.

Problem 6.2
You learned that the ElGamal scheme is not IND-CCA secure, so consider the following variant of
the scheme.
Let p and q be large primes such that q divides p-1. Let G be the order q subgroup generated by
ginG. Assume that the DDH assumption holds in G. Consider the following scheme EG'=(K,E,D)
defined with Message space Zp** and ciphertext space (GZp**) :
Algorithm EK(M),
Algorithm K,ylarr$Zq Algorithm DK(Y,W)
xlarr&Zq,Ylarrgy,KlarrYx
xlarrgx,Klarrxy,MlarrW*K-1
Return (x,x),WlarrK*M return M
Return (Y,W),
Show that EG' is still not secure under IND-CCA even if DDH is hard for G,g.(Remember that
adversaries know the public parameters G,g,q.)
Problem 6 . 2 You learned that the ElGamal scheme

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!