Re: Weak keys for ElGamal



Anton Berg <antonberg1@xxxxxx> wrote:
I am sure, that this is not possible because the computation of the
discrete logarithm is random-self-reducible.

If you are sure, you should try to prove it. (Start with the assumption
that there exists some significant set of weak keys for ElGamal. Then
try a random self-reduction and see what the advantage is.)

--
Kristian Gjøsteen
.