Loading Seminars

« All Seminars

  • This seminar has passed.

On the (in)security of ElGamal in OpenPGP

26 January 2022 @ 3:00 pm - 4:00 pm

Do you think you know ElGamal encryption? Think twice.

We uncover vulnerabilities in the OpenPGP ecosystem stemming from confusion about the definition of ElGamal encryption (and the lack of an unequivocable standard). The first vulnerability leads to practical plaintext recovery in a limited number of cases. The second one, combined with side-channel leakage we found in some popular OpenPGP libraries, leads to feasible key recovery, in relatively rare cases.

We hope that these attacks, that we dub “cross-configuration”, serve as a cautionary tale for standards designers. Cryptographic algorithms, even when they may appear very simple, hide a great deal of complexity in the choices of parameters and data representation. While an instantiation may appear to be safe in isolation, the interaction of two incompatible instantiations may lead to a security disaster, which can only be avoided by a carefully written standard.

Joint work with Bertram Poettering and Alessandro Sorniotti.

Zoom Meeting: https://newcastleuniversity.zoom.us/j/87494431621?pwd=eHhVZm1iS1NRd1FRbHhsTVI0N3NXdz09

Meeting ID: 874 9443 1621
Passcode: 145917

Youtube live streaming: https://youtu.be/ncCKpxPJcdw

Youtube VoD


26 January 2022
3:00 pm - 4:00 pm
Seminar Tags:


Luca De Feo (IBM Research)

Luca De Feo received his PhD from École Polytechnique (France) in 2010, with a thesis on computer algebra and computational number theory. He then joined Université de Versailles (France) in 2011 as Assistant Professor, where he kept working on computer algebra and cryptography. He is currently employed at IBM Research, where he works on post-quantum cryptography and related topics.

Leave a Reply