On the CCA1-security of Elgamal and Damgård's Elgamal

  • Authors:
  • Helger Lipmaa

  • Affiliations:
  • Cybernetica AS, Estonia and Tallinn University, Estonia

  • Venue:
  • Inscrypt'10 Proceedings of the 6th international conference on Information security and cryptology
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

It is known that there exists a reduction from the CCA1- security of Damgård's Elgamal (DEG) cryptosystem to what we call the ddhdsdh assumption. We show that ddhdsdh is unnecessary for DEG- CCA1, while DDH is insufficient for DEG-CCA1. We also show that CCA1-security of the Elgamal cryptosystem is equivalent to another assumption ddhcsdh, while we show that ddhdsdh is insufficient for Elgamal's CCA1-security. Finally, we prove a generic-group model lower bound Ω(3√q) for the hardest considered assumption ddhcsdh, where q is the largest prime factor of the group order.