October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

ElGamal Algorithm Explained: How the Encryption Works

ElGamal is randomized public-key encryption over a cyclic group. See how its two-part ciphertext works, how the private exponent decrypts it, and why ElGamal encryption is distinct from signatures and DSA.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ElGamal encryption is a randomized public-key method that protects a message by combining it with a fresh secret value in a cyclic group. The recipient uses a private exponent to remove that mask. Its security depends on the group and variant chosen; it is not a blanket guarantee for every construction called ElGamal.

What is the ElGamal algorithm?

ElGamal encryption is a public-key encryption construction over a cyclic group. The recipient publishes a group element derived from a secret exponent. A sender uses that public key and fresh randomness to produce a two-part ciphertext; the recipient’s private exponent lets them recover the message.

As an Amazon Associate I earn from qualifying purchases.

The spelling most commonly used in technical writing is ElGamal, although the name is also written as “El Gamal.” The equations below describe the basic encryption construction, not ElGamal signature schemes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How does ElGamal encryption work?

Let the group be written multiplicatively, with generator g and order q. Group elements are the values on which the scheme operates. The recipient creates a key pair as follows:

  1. Choose a private exponent x.
  2. Compute the public value h = g^x.
  3. Publish the group parameters and h; keep x secret.

To encrypt a plaintext represented by a group element m, the sender chooses fresh random r and computes:

  • c1 = g^r
  • c2 = m · h^r

The ciphertext is the pair (c1, c2). The random value r creates a temporary mask, h^r, which is multiplied by the message in the second component.

Decryption removes the mask

The recipient computes c2 / c1^x. Since c1^x = (g^r)^x = g^(rx) = (g^x)^r = h^r, the division cancels the mask and leaves m. The key-generation, encryption, and decryption construction is described in the UPF cryptography lecture notes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does encryption use fresh randomness?

The sender must choose fresh randomness for each encryption. Encrypting the same plaintext again can therefore produce a different ciphertext. This randomization is a defining feature of the basic construction, not an optional formatting step.

The same lecture notes state a security proposition based on the decisional Diffie–Hellman (DDH) problem being hard in the group used. That statement applies to the scheme and group under discussion; it should not be generalized to every ElGamal variant. The notes also give a useful intuition: an attacker able to compute discrete logarithms could recover the private exponent and then decrypt. This intuition is distinct from the stated DDH-based proposition.

In practice, security also depends on appropriate parameter and group choices, a secure source of randomness, and correct handling of group elements. The mathematical description alone does not establish that a particular implementation is safe.

What if the message is a small integer?

A related lifted-ElGamal form encodes a small integer message m as g^m. The ciphertext becomes (g^r, g^m h^r). After removing h^r, the recipient solves for the small exponent m. This can be practical when the possible message range is small; it does not make the general discrete-log problem easy. The cited lecture notes describe this encoding as a way to handle small messages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is ElGamal the same as DSA?

No. ElGamal encryption provides confidentiality, while a signature scheme provides a way to verify a message’s origin and integrity. The name also refers to related signature constructions, which should not be confused with the encryption equations above.

RFC 6090, an informational RFC dated February 2011, says the ElGamal signature algorithm was introduced in 1984 and is based on the discrete-logarithm problem. It describes the original scheme in the multiplicative group modulo a large prime and identifies DSA as an important ElGamal signature variant. For signatures on arbitrary-length messages, the RFC says a collision-resistant hash function is needed to avoid existential forgery attacks. Those signature-specific requirements are not a blanket description of basic ElGamal encryption.

Is ElGamal encryption still used?

It remains useful for understanding public-key cryptography and appears in standards-related contexts, but suitability depends on the protocol and profile. For example, the current OpenPGP specification, RFC 9580, says implementations must not generate Elgamal keys or encrypt using them. It also says a decrypting implementation should warn that an Elgamal secret key is too weak for modern use. This is guidance for Elgamal within that OpenPGP profile, not a claim that the underlying mathematics has no educational or research relevance.

RFC 9580 states in Section 12.6: “An implementation MUST NOT encrypt using Elgamal keys.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.