Free tools Windows power users keep installed
One-click scans. No signup required.
ElGamal encryption is a randomized public-key method that protects a message by combining it with a fresh secret value in a cyclic group. The recipient uses a private exponent to remove that mask. Its security depends on the group and variant chosen; it is not a blanket guarantee for every construction called ElGamal.
What is the ElGamal algorithm?
ElGamal encryption is a public-key encryption construction over a cyclic group. The recipient publishes a group element derived from a secret exponent. A sender uses that public key and fresh randomness to produce a two-part ciphertext; the recipient’s private exponent lets them recover the message.
As an Amazon Associate I earn from qualifying purchases.
The spelling most commonly used in technical writing is ElGamal, although the name is also written as “El Gamal.” The equations below describe the basic encryption construction, not ElGamal signature schemes.
How does ElGamal encryption work?
Let the group be written multiplicatively, with generator g and order q. Group elements are the values on which the scheme operates. The recipient creates a key pair as follows:
#1 Best Overall
- Choose a private exponent
x. - Compute the public value
h = g^x. - Publish the group parameters and
h; keepxsecret.
To encrypt a plaintext represented by a group element m, the sender chooses fresh random r and computes:
c1 = g^rc2 = m · h^r
The ciphertext is the pair (c1, c2). The random value r creates a temporary mask, h^r, which is multiplied by the message in the second component.
Decryption removes the mask
The recipient computes c2 / c1^x. Since c1^x = (g^r)^x = g^(rx) = (g^x)^r = h^r, the division cancels the mask and leaves m. The key-generation, encryption, and decryption construction is described in the UPF cryptography lecture notes.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhy does encryption use fresh randomness?
The sender must choose fresh randomness for each encryption. Encrypting the same plaintext again can therefore produce a different ciphertext. This randomization is a defining feature of the basic construction, not an optional formatting step.
The same lecture notes state a security proposition based on the decisional Diffie–Hellman (DDH) problem being hard in the group used. That statement applies to the scheme and group under discussion; it should not be generalized to every ElGamal variant. The notes also give a useful intuition: an attacker able to compute discrete logarithms could recover the private exponent and then decrypt. This intuition is distinct from the stated DDH-based proposition.
In practice, security also depends on appropriate parameter and group choices, a secure source of randomness, and correct handling of group elements. The mathematical description alone does not establish that a particular implementation is safe.
Rank #4
What if the message is a small integer?
A related lifted-ElGamal form encodes a small integer message m as g^m. The ciphertext becomes (g^r, g^m h^r). After removing h^r, the recipient solves for the small exponent m. This can be practical when the possible message range is small; it does not make the general discrete-log problem easy. The cited lecture notes describe this encoding as a way to handle small messages.
Is ElGamal the same as DSA?
No. ElGamal encryption provides confidentiality, while a signature scheme provides a way to verify a message’s origin and integrity. The name also refers to related signature constructions, which should not be confused with the encryption equations above.
RFC 6090, an informational RFC dated February 2011, says the ElGamal signature algorithm was introduced in 1984 and is based on the discrete-logarithm problem. It describes the original scheme in the multiplicative group modulo a large prime and identifies DSA as an important ElGamal signature variant. For signatures on arbitrary-length messages, the RFC says a collision-resistant hash function is needed to avoid existential forgery attacks. Those signature-specific requirements are not a blanket description of basic ElGamal encryption.
Is ElGamal encryption still used?
It remains useful for understanding public-key cryptography and appears in standards-related contexts, but suitability depends on the protocol and profile. For example, the current OpenPGP specification, RFC 9580, says implementations must not generate Elgamal keys or encrypt using them. It also says a decrypting implementation should warn that an Elgamal secret key is too weak for modern use. This is guidance for Elgamal within that OpenPGP profile, not a claim that the underlying mathematics has no educational or research relevance.
RFC 9580 states in Section 12.6: “An implementation MUST NOT encrypt using Elgamal keys.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




