On the (In)Security of ElGamal in OpenPGP.

Saved in:
Bibliographic Details
Title: On the (In)Security of ElGamal in OpenPGP.
Authors: De Feo, Luca1 feo@zurich.ibm.com, Poettering, Bertram1 poe@zurich.ibm.com, Sorniotti, Alessandro1 aso@zurich.ibm.com
Source: Communications of the ACM. Jun2023, Vol. 66 Issue 6, p107-115. 9p. 1 Black and White Photograph, 2 Charts, 3 Graphs.
Subjects: Public key cryptography, Email security, Ciphers, Privacy, Logarithms
Abstract: Roughly four decades ago, Taher ElGamal put forward what is today one of the most widely known and best understood public key encryption schemes. ElGamal encryption has been used in many different contexts, chiefly among them by the OpenPGP email encryption standard. Despite its simplicity, or perhaps because of it, in reality there is a large degree of ambiguity on several key aspects of the cipher. Each library in the OpenPGP ecosystem seems to have implemented a slightly different "flavor" of ElGamal encryption. While-taken in isolation-each implementation may be secure, we reveal that in the interoperable world of OpenPGP, unforeseen cross-configuration attacks become possible. Concretely, we propose different such attacks and show their practical efficacy by recovering plaintexts and even secret keys. [ABSTRACT FROM AUTHOR]
Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 163907063
AccessLevel: 6
PubType: Periodical
PubTypeId: serialPeriodical
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: On the (In)Security of ElGamal in OpenPGP.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22De+Feo%2C+Luca%22">De Feo, Luca</searchLink><relatesTo>1</relatesTo><i> feo@zurich.ibm.com</i><br /><searchLink fieldCode="AR" term="%22Poettering%2C+Bertram%22">Poettering, Bertram</searchLink><relatesTo>1</relatesTo><i> poe@zurich.ibm.com</i><br /><searchLink fieldCode="AR" term="%22Sorniotti%2C+Alessandro%22">Sorniotti, Alessandro</searchLink><relatesTo>1</relatesTo><i> aso@zurich.ibm.com</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Communications+of+the+ACM%22">Communications of the ACM</searchLink>. Jun2023, Vol. 66 Issue 6, p107-115. 9p. 1 Black and White Photograph, 2 Charts, 3 Graphs.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Public+key+cryptography%22">Public key cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Email+security%22">Email security</searchLink><br /><searchLink fieldCode="DE" term="%22Ciphers%22">Ciphers</searchLink><br /><searchLink fieldCode="DE" term="%22Privacy%22">Privacy</searchLink><br /><searchLink fieldCode="DE" term="%22Logarithms%22">Logarithms</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Roughly four decades ago, Taher ElGamal put forward what is today one of the most widely known and best understood public key encryption schemes. ElGamal encryption has been used in many different contexts, chiefly among them by the OpenPGP email encryption standard. Despite its simplicity, or perhaps because of it, in reality there is a large degree of ambiguity on several key aspects of the cipher. Each library in the OpenPGP ecosystem seems to have implemented a slightly different "flavor" of ElGamal encryption. While-taken in isolation-each implementation may be secure, we reveal that in the interoperable world of OpenPGP, unforeseen cross-configuration attacks become possible. Concretely, we propose different such attacks and show their practical efficacy by recovering plaintexts and even secret keys. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=163907063
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1145/3592835
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 9
        StartPage: 107
    Subjects:
      – SubjectFull: Public key cryptography
        Type: general
      – SubjectFull: Email security
        Type: general
      – SubjectFull: Ciphers
        Type: general
      – SubjectFull: Privacy
        Type: general
      – SubjectFull: Logarithms
        Type: general
    Titles:
      – TitleFull: On the (In)Security of ElGamal in OpenPGP.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: De Feo, Luca
      – PersonEntity:
          Name:
            NameFull: Poettering, Bertram
      – PersonEntity:
          Name:
            NameFull: Sorniotti, Alessandro
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 06
              Text: Jun2023
              Type: published
              Y: 2023
          Identifiers:
            – Type: issn-print
              Value: 00010782
          Numbering:
            – Type: volume
              Value: 66
            – Type: issue
              Value: 6
          Titles:
            – TitleFull: Communications of the ACM
              Type: main
ResultId 1