You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Then Eve can take the inverse modulo $p$ to obtain $g^{ab}\text{ (mod }p\text{)}$.
Smarter decryption oracle
Note
Now the oracle know that it should never decrypt ciphertexts having $c_2=1$.
So Even chooses an arbitrary value for $c_2$ and set $c_1=B$. Then she tells the oracle that the public key is $A$ and give the ciphertext $(c_1,c_2)$.
The oracle retain the plaintext $m$ that satisfies