ElGamal public key cryptosystem based on the discrete logarithm problem in finite fields. Provides semantic security through randomized encryption: every message is encrypted under a fresh ephemeral exponent. Uses the published MODP groups of RFC 3526 with EME-PKCS1-v1_5 message encoding.
| Property | Value |
|---|---|
| Category | Asymmetric Ciphers |
| Sub-category | Public Key Cryptosystem |
| Security status | π Educational Only |
| Complexity | Advanced |
| Inventor | Taher ElGamal |
| Year | 1985 |
| Origin | πΊπΈ United States |
| Source | algorithms/asymmetric/elgamal.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 1536 bytes (12288 bits); 2048 bytes (16384 bits) |
Status: π Educational Only
| Issue | Description | Mitigation |
|---|---|---|
| Small Subgroup Attack | β | Ensure prime p is a safe prime (p = 2q + 1 where q is prime) to prevent small subgroup attacks. The RFC 3526 groups used here are safe primes |
| Chosen Ciphertext Attack | β | Basic ElGamal is malleable and not CCA-secure: multiplying c2 by a constant multiplies the plaintext by it. Use a CCA-secure construction for production |
| Published Demonstration Key | β | The private exponent in this file is printed in the source and confers no confidentiality. Supply real key material through the publicKey/privateKey properties for any use beyond demonstration |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β ElGamal over RFC 3526 group 5 - round-trip
| Field | Value |
|---|---|
key |
0600 |
input |
456c47616d616c2054657374 |
expected |
456c47616d616c2054657374 |
Vector 2 β ElGamal over RFC 3526 group 14 - round-trip with leading zero octets
| Field | Value |
|---|---|
key |
0800 |
input |
0000000102030405 |
expected |
0000000102030405 |
Vector 3 β ElGamal over RFC 3526 group 14 - round-trip of an all-zero message
| Field | Value |
|---|---|
key |
0800 |
input |
0000000000000000 |
expected |
0000000000000000 |