Score:0

Decryption of ElGamal ciphertext

us flag

If someone says that the decryption of an ElGamal ciphertext is "x", how can I be sure that the real value is "x" and not "y", even if he is the owner of the respective private key?

Ievgeni avatar
cn flag
Precise the context: Static/interactive? Bilinear group or not?
Score:0
ru flag

Assuming you are using El Gamal encryption in a group where the decisional Diffie-Hellman problem is hard, you cannot. El Gamal is known to be IND-CPA in such groups.

If DDH is tractable and they assert that the cryptogram $(n,c)$ is of the form $(g^r,xa^r)$ then you can check $\mathrm{DDH}(g,a,n,c/x)$.

You can ask for additional information to prove their assertion, but this exceeds the parameters of your question.

kelalaka avatar
in flag
This is about commitment or zero-knowledge.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.