ElGamal signature scheme (source code)

= ElGamal signature scheme
{c}
{wiki}

= ElGamal signature
{c}
{synonym}

For a <prime number> $p$, <primitive root> $g$ and <public key> $y=g^a$, choose a fresh secret $k$ <coprime> to $p-1$, set $r=g^k\pmod p$ and $s=k^{-1}(H(m)-ar)\pmod{p-1}$, and verify $g^{H(m)}=y^r r^s\pmod p$. Reusing the <cryptographic nonce> can reveal secret information. The unhashed historical construction allows existential forgery of specially chosen message exponents, so authentication claims require suitable hashing and protocol assumptions.