1 of 23

Jonathan Berger

Introduction to Cyber Security

TA 5: PKI – Diffie Hellman

Based on slides of Benny Pinkas and Gil Segev

2 of 23

A Reminder – Decisional Diffie-Hellman Assumption

 

 

2

3 of 23

A Reminder - Diffie-Hellman Key-Agreement

 

Alice

Bob

 

 

 

 

 

 

 

3

4 of 23

Diffie-Hellman Key-Agreement

 

Alice

Bob

 

 

 

 

 

 

4

5 of 23

Diffie-Hellman Key-Agreement (cont.)

 

 

Alice

Bob

 

 

 

 

 

 

 

 

Eve

 

 

5

6 of 23

Public Key Encryption

6

7 of 23

Public-Key Encryption

 

 

 

 

 

 

 

 

7

8 of 23

Chosen-Plaintext Attacks (CPA)

 

 

 

 

 

 

 

 

 

 

 

 

8

9 of 23

Public Key Encryption from Key Exchange

  • Suppose that we have an arbitrary key exchange protocol which has exactly two messages

Alice

Bob

 

 

 

 

 

9

10 of 23

The Encryption scheme

 

GEN

ENC

DEC

Alice

Bob

 

 

 

 

 

10

11 of 23

El-Gamal Encryption

  • A PKE scheme based on the Diffie-Hellman key-agreement protocol

11

12 of 23

El-Gamal Encryption

 

 

 

12

13 of 23

The Security of El-Gamal Encryption

 

 

 

13

14 of 23

The Security of El-Gamal Encryption

 

 

 

14

15 of 23

Malleability of El-Gamal Encryption

 

15

16 of 23

El-Gamal Encryption is not CCA-Secure

 

 

16

17 of 23

El-Gamal Encryption is not CCA-Secure (cont.)

 

17

18 of 23

Exercise

 

 

 

18

19 of 23

Exercise (cont.)

 

 

19

20 of 23

Application Example – Simple Voting

 

Alice

 

 

 

 

20

21 of 23

Application Example – Simple Voting (cont.)

 

Alice

 

 

 

 

21

22 of 23

22

23 of 23

Questions?