Binding ElGamal: A Fraud-Detectable Alternative to Key-Escrow Proposals
Eric R. Verheul5
and Henk C. A. van Tilborg6 
| (5) |
Ministry of the Interior, P.O. Box 20010, 2500 EA The Hague, The Netherlands |
| (6) |
Department of Math. and Comp. Sc., Eindhoven University of Technology, P.O. Box 513, 5600 MB Eindhoven, The Netherlands |
Abstract
We propose a concept for a worldwide information security infrastructure that protects law-abiding citizens, but not criminals,
even if the latter use it fraudulently (i.e. when not complying with the agreed rules). It can be seen as a middle course
between the inflexible but fraud-resistant KMI-proposal [8] and the flexible but non-fraud-resistant concept used in TIS-CKE [2]. Our concept consists of adding binding data to the latter concept, which will not prevent fraud by criminals but makes it at least detectable by third parties without the need of any secret information. In [19], we depict a worldwide framework in which this concept could present a security tool that is flexible enough to be incorporated
in any national cryptography policy, on both the domestic and foreign use of cryptography. Here, we present a construction
for binding data for ElGamal type public key encryption schemes. As a side result we show that a particular simplification
in a multiuser version of ElGamal does not affect its security.
Key words ElGamal - Traceable ElGamal - Key Escrow - Key Recovery
Views expressed here are personal and not necessarily shared by my employer.
References secured to subscribers.