Llcipher logo

Cryptography Challenges

El Gamal Challenge: Randomness Reuse Attack

The Problem: Given an encryption key, two ciphertexts which use the same random exponent y and the plaintext corresponding to one of those ciphertexts, recover the second plaintext.

You intercept two ciphertexts cM and cA intended for Horridland; one from Malland, and one from Awfulland. Your agent in Awfulland figures out what Awfulland wants to communicate to Horridland; it is "I'm following your lead". Since Malland has always been their plan-maker, in order to determine what Horridland, Malland and Awfulland will do, you need to figure out what Malland is communicating to Horridland. You know that your enemies are pretty bad at using cryptography, and that they sometimes forget to pick fresh randomness. You suspect that they might have used the same random value y to create both ciphertexts. Use this knowledge to figure out what Malland is trying to tell Horridland.

For this exercise, use the following values:

Name Value
Modulus p
81785994127709318289853065761955524169138231746284711479485415030808910423027
Generator g
22516865910468801601308561429639052930860860822537909007768722786312195121817
Public key y
36433769016903874501658143656773481666618078895123392319688941652668647230923
First value of Awfulland's ciphertext cA1
2724206478530501383338955345475383902782782029131830001349892847110599761342
Second value of Awfulland's ciphertext cA2
56947492839998276292281585728777115971816528660471377149682848374783094180495
First value of Malland's ciphertext cM1
2724206478530501383338955345475383902782782029131830001349892847110599761342
Second value of Malland's ciphertext cM2
77238632939744196443596630152689692898162213353150931759835351038294784582439