作者: Helger Lipmaa
DOI: 10.1007/978-3-642-21518-6_2
关键词:
摘要: It is known that there exists a reduction from the CCA1- security of Damgard's Elgamal (DEG) cryptosystem to what we call ddhdsdh assumption. We show unnecessary for DEG- CCA1, while DDH insufficient DEG-CCA1. also CCA1-security equivalent another assumption ddhcsdh, Elgamal's CCA1-security. Finally, prove generic-group model lower bound Ω(3√q) hardest considered where q largest prime factor group order.