Publications: Abstract

Generating {ElGamal} Signatures Without Knowing the Secret Key

Daniel Bleichenbacher

We present a new method to forge ElGamal signatures if the public parameters of the system are not chosen properly. Since the secret key is hereby not found this attack shows that forging ElGamal signatures is sometimes easier than the underlying discrete logarithm problem.