Hawkynt

ElGamal

ElGamal public key cryptosystem based on the discrete logarithm problem in finite fields. Provides semantic security through randomized encryption: every message is encrypted under a fresh ephemeral exponent. Uses the published MODP groups of RFC 3526 with EME-PKCS1-v1_5 message encoding.

Properties

Property Value
Category Asymmetric Ciphers
Sub-category Public Key Cryptosystem
Security status πŸŽ“ Educational Only
Complexity Advanced
Inventor Taher ElGamal
Year 1985
Origin πŸ‡ΊπŸ‡Έ United States
Source algorithms/asymmetric/elgamal.js

Parameters

Parameter Supported values
Key sizes 1536 bytes (12288 bits); 2048 bytes (16384 bits)

Security

Status: πŸŽ“ Educational Only

Known vulnerabilities

Issue Description Mitigation
Small Subgroup Attack β€” Ensure prime p is a safe prime (p = 2q + 1 where q is prime) to prevent small subgroup attacks. The RFC 3526 groups used here are safe primes
Chosen Ciphertext Attack β€” Basic ElGamal is malleable and not CCA-secure: multiplying c2 by a constant multiplies the plaintext by it. Use a CCA-secure construction for production
Published Demonstration Key β€” The private exponent in this file is printed in the source and confers no confidentiality. Supply real key material through the publicKey/privateKey properties for any use beyond demonstration

Documentation

References

Test vectors

3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 β€” ElGamal over RFC 3526 group 5 - round-trip

Field Value
key 0600
input 456c47616d616c2054657374
expected 456c47616d616c2054657374

Vector 2 β€” ElGamal over RFC 3526 group 14 - round-trip with leading zero octets

Field Value
key 0800
input 0000000102030405
expected 0000000102030405

Vector 3 β€” ElGamal over RFC 3526 group 14 - round-trip of an all-zero message

Field Value
key 0800
input 0000000000000000
expected 0000000000000000

← All algorithms