Is it safe to use Pohlig-Hellman encryption with a common modulus?  
That is, I want various parties to have their own exponents, but share 
the same prime modulus.  In my application, a chosen plaintext attack 
will be possible.  (I know that RSA with common modulus is not safe.)

                --Steve Bellovin, http://www.research.att.com/~smb


---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to [EMAIL PROTECTED]

Reply via email to