The elgamal signature scheme Signing Letm∈Zn* be a message For k=(p,g, x,y y=gx mod pi, and secret random number k∈Zn1* p-1, define: sigr(m, k)=(S,t),where 8 mod t=(m-xs)k mod p-1(kt +xs =m mod p-1) Ⅴ erification verk(m, (s, t))=true e stys=gm mod p sl,ys=gkt gxs=gm mod pe kt+xs =m mod p-1 2222 The ElGamal signature scheme • Signing Let m Zp* be a message. For K = {(p,g,x,y): y = g x mod p }, and secret random number k Zp-1 *, define: sigK(m,k) = (s,t), where – s = gk mod p – t = (m-xs)k-1 mod p-1(kt +xs =m mod p-1 ) • Verification verK(m,(s,t)) = true st·ys = gm mod p . s t·ys =gkt· g xs = gm mod p kt +xs =m mod p-1