-----BEGIN PGP SIGNED MESSAGE----- aba@dcs.ex.ac.uk wrote:
PGP has been standardising on El Gamal which is not covered by RSA's patents, for precisely the reason that RSA Inc has a bad record as a litigious patent worker. El Gamal is a variant of Diffie-Hellman, and the patents on Diffie-Hellman are set to expire RSN (later this year, Sept?)
How does El Gamal compare functionally and security-wise to RSA and who developed it?
I think that the initial PGP products are using RSA, however I understood PGP is moving to El Gamal, where RSA is due to be relegated to a `for backwards compatibility only' feature.
Is El Gamal used in the source for PGP 3.0? Ciao Harka -----BEGIN PGP SIGNATURE----- Version: 2.6.2 iQEVAwUBM3JpGjltEBIEF0MBAQFDfQf8CawUGU1ynDlmcmsloy7zsh5oQUhcxPSv Luy17oVmbWVeCWpCbqqiWFoRh1+QzBBc8Yfbb2/2LOw1KFyIq5lQ8Ly64JPuVMgV HUocUDnPE7Q18eVVXOfNyG6vg/s0PBRqREVrx1QWn37idPduMTg0TE/IHZqFVrso 3XdVroh41aX7qVnan2+nRnVCbrV9xMvNteWOUl/nADLHCAkoMl/eCcQVY/XSmFjc SsUbNNgCDBJlZhAwAI/CBLM7CBVt4okZQkdKeLNWsrm1tG2yha7vl/2AI6k1Y70H 2g1zTrhqK7q/rqkNL6DKyam/NZ1FKXtO0BsTLsV6KqmI7SnGN4UZXw== =f4Qu -----END PGP SIGNATURE-----
At 4:00 PM -0800 5/8/97, harka@nycmetro.com wrote:
How does El Gamal compare functionally and security-wise to RSA and who developed it?
Yes, who did develop El Gamal? Could it have been....El Gamal? (Or was that a trick question?) --Tim May There's something wrong when I'm a felon under an increasing number of laws. ---------:---------:---------:---------:---------:---------:---------:---- Timothy C. May | Crypto Anarchy: encryption, digital money, tcmay@got.net 408-728-0152 | anonymous networks, digital pseudonyms, zero W.A.S.T.E.: Corralitos, CA | knowledge, reputations, information markets, Higher Power: 2^1398269 | black markets, collapse of governments. "National borders aren't even speed bumps on the information superhighway."
Tim May <tcmay@got.net> writes:
How does El Gamal compare functionally and security-wise to RSA and who developed it?
Yes, who did develop El Gamal?
Could it have been....El Gamal?
What's El Gamal up to these days? I heard he used to work for Okidata as a low-level manager and had to leave when both of his subordinates resigned at the same time. :-) Is that true? Why won't Sameer "Gas the Kikes" Parekh hire his fellow Arab? --- Dr.Dimitri Vulis KOTM Brighton Beach Boardwalk BBS, Forest Hills, N.Y.: +1-718-261-2013, 14.4Kbps
nobody@REPLAY.COM (Anonymous) writes:
Vulis wrote re ElGamal:
Why won't Sameer "Gas the Kikes" Parekh hire his fellow Arab?
Because Sameer's competition already hired him. Get a clue...
Okidata is competing with Sameer? After failing as an ISP and as a web server vendor, Sameer decided to switch to peddling printers? Or is Sameer diversifying into Usenet newsreaders with no killfiles? --- Dr.Dimitri Vulis KOTM Brighton Beach Boardwalk BBS, Forest Hills, N.Y.: +1-718-261-2013, 14.4Kbps
Dimitri Vulis <dlv@bwalk.dm.com> writes:
nobody@REPLAY.COM (Anonymous) writes:
Vulis wrote re ElGamal:
Why won't Sameer "Gas the Kikes" Parekh hire his fellow Arab?
Because Sameer's competition already hired him. Get a clue...
Okidata is competing with Sameer?
Taher El Gamal works for Netscape now... Adam
Harka <harka@nycmetro.com> writes:
Adam Back <aba@dcs.ex.ac.uk> wrote:
PGP has been standardising on El Gamal which is not covered by RSA's patents, for precisely the reason that RSA Inc has a bad record as a litigious patent worker. El Gamal is a variant of Diffie-Hellman, and the patents on Diffie-Hellman are set to expire RSN (later this year, Sept?)
How does El Gamal compare functionally and security-wise to RSA and who developed it?
Functionally: it provides both a digital signature method and an assymetric encryption method. They are not self-inverses as in RSA (in RSA encrypt with secret key = signature, encrypt with public key = assymetric encrypt; with El Gamal encrypt and sign are different operations). Security: EG is based on the discrete log problem (being a variant of Diffie-Hellman) where as RSA is based on the factoring problem. Discrete log has about the same security for the same size keys. El Gamal encrypted blocks and signatures are twice the size as RSA blocks, there is a 2x expansion. If you don't mine a common prime modulus with EG, key generation is fast (just generate a random number), RSA key generation is _slow_. There is no separate patent on EG. The D-H patent, which the patent holders may argue covers EG, expires as I said RSN so the attraction of EG is that it will then be unencumbered by patents. El Gamal was developed by Taher El Gamal. I don't see the advantage of EG encryption, D-H achieves the same thing with the same security and it doesn't have message expansion. There is a difference, with D-H you can't choose the session key directly, it is negotiated and depends on the encryptors choice of negotiation parameter and the recipients secret key. However most uses of public key encryption are only interested in exchanging or negotating a symmetric key anyway, so D-H seems practical for this purpose. Is there any speed advantage with EG encryption? EG signatures and D-H encryption? You can share the prime modulus public key parameter.
I think that the initial PGP products are using RSA, however I understood PGP is moving to El Gamal, where RSA is due to be relegated to a `for backwards compatibility only' feature.
Is El Gamal used in the source for PGP 3.0?
I don't know, no one's exported the source to pgp3.0 in electronic form, and I haven't seen the books either. PGP4.5 (which has been exported, was on ftp://ftp.replay.com last I looked) seems to use RSA still. It has the added functionality of a windows front end, separate signing and encryption keys, and expiry dates on keys. Adam
participants (6)
-
Adam Back
-
dlv@bwalk.dm.com
-
harka@nycmetro.com
-
Mac Norton
-
nobody@REPLAY.COM
-
Tim May