{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T23:15:58Z","timestamp":1763507758408,"version":"3.45.0"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,12]],"date-time":"2021-11-12T00:00:00Z","timestamp":1636675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EU Horizon 2020 research and innovation programme","award":["No 786725 OLYMPUS"],"award-info":[{"award-number":["No 786725 OLYMPUS"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,12]]},"DOI":"10.1145\/3460120.3485257","type":"proceedings-article","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T12:05:33Z","timestamp":1636805133000},"page":"2066-2080","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["On the (In)Security of ElGamal in OpenPGP"],"prefix":"10.1145","author":[{"given":"Luca","family":"De Feo","sequence":"first","affiliation":[{"name":"IBM Research Europe - Zurich, R\u00fcschlikon, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bertram","family":"Poettering","sequence":"additional","affiliation":[{"name":"IBM Research Europe - Zurich, R\u00fcschlikon, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessandro","family":"Sorniotti","sequence":"additional","affiliation":[{"name":"IBM Research Europe - Zurich, R\u00fcschlikon, Switzerland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2018. CVE-2018-6594. https:\/\/www.cvedetails.com\/cve\/CVE-2018-6594\/."},{"key":"e_1_3_2_2_2_1","unstructured":"2018. CVE-2018-6829. https:\/\/www.cvedetails.com\/cve\/CVE-2018-6829\/."},{"volume-title":"OpenPGP server key dump from 15\/01\/2021. https:\/\/pgp.key-server.io\/dump\/. [Online","year":"2021","key":"e_1_3_2_2_3_1","unstructured":"2021. OpenPGP server key dump from 15\/01\/2021. https:\/\/pgp.key-server.io\/dump\/. [Online; accessed 15\/01\/2021]."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/11967668_15"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.42"},{"key":"e_1_3_2_2_6_1","first-page":"435","article-title":"Wait a minute! A fast, Cross-VM attack on AES","volume":"2014","author":"Apecechea Gorka Irazoqui","year":"2014","unstructured":"Gorka Irazoqui Apecechea, Mehmet Sinan Inci, Thomas Eisenbarth, and Berk Sunar. 2014. Wait a minute! A fast, Cross-VM attack on AES. IACR Cryptol. ePrint Arch., Vol. 2014 (2014), 435. http:\/\/eprint.iacr.org\/2014\/435","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--319--24174--6_22"},{"key":"e_1_3_2_2_8_1","unstructured":"Daniel J. Bernstein. 2005. Cache-timing attacks on AES. Technical Report."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/3--540--68339--9_2"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/3--540--44448--3_3"},{"volume-title":"Handbook of markov chain monte carlo","author":"Brooks Steve","key":"e_1_3_2_2_11_1","unstructured":"Steve Brooks, Andrew Gelman, Galin Jones, and Xiao-Li Meng. 2011. Handbook of markov chain monte carlo .CRC press."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"Jon Callas Lutz Donnerhacke Hal Finney David Shaw and Rodney Thayer. 2007. OpenPGP Message Format. https:\/\/www.rfc-editor.org\/rfc\/rfc4880.html","DOI":"10.17487\/rfc4880"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/844102.844108"},{"key":"e_1_3_2_2_14_1","volume-title":"CRYPTO'84 (LNCS","volume":"18","author":"ElGamal Taher","year":"1984","unstructured":"Taher ElGamal. 1984. A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms. In CRYPTO'84 (LNCS, Vol. 196), G. R. Blakley and David Chaum (Eds.). Springer, Heidelberg, 10--18."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Luca De Feo Bertram Poettering and Alessandro Sorniotti. 2021. On the (In)Security of ElGamal in OpenPGP. Cryptology ePrint Archive Report 2021\/923. https:\/\/ia.cr\/2021\/923 .","DOI":"10.1145\/3460120.3485257"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--662--48324--4_11"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--319--40667--1_14"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/3--540--44499--8_23"},{"key":"e_1_3_2_2_19_1","volume-title":"Ronald Henry Tse, Derek Atkins, and Daniel Kahn Gillmor.","author":"Koch Werner","year":"2020","unstructured":"Werner Koch, brian m. carlson, Ronald Henry Tse, Derek Atkins, and Daniel Kahn Gillmor. 2020. OpenPGP Message Format. Internet-Draft draft-ietf-openpgp-rfc4880bis-10. Internet Engineering Task Force. https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-openpgp-rfc4880bis-10 Work in Progress."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.2307\/1971363"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0052240"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_2_2_23_1","volume-title":"Vanstone","author":"Menezes Alfred J.","year":"1997","unstructured":"Alfred J. Menezes, Paul C. van Oorschot, and Scott A. Vanstone. 1997. Handbook of Applied Cryptography .CRC Press, 2000 N.W. Corporate Blvd., Boca Raton, FL 33431--9868, USA. xxviii+ 780 pages. QA76.9.A25 M463 1997"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/3--540--48059--5_14"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2011.05.027"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/11693383_6"},{"key":"e_1_3_2_2_27_1","volume-title":"The Future of Integer Factorization. CryptoBytes (The technical newsletter of RSA Laboratories)","author":"Odlyzko Andrew M","year":"1995","unstructured":"Andrew M Odlyzko. 1995. The Future of Integer Factorization. CryptoBytes (The technical newsletter of RSA Laboratories), Vol. 1, 2 (1995), 5--12. http:\/\/www.dtc.umn.edu\/ odlyzko\/doc\/future.of.factoring.pdf"},{"key":"e_1_3_2_2_28_1","volume-title":"27th USENIX Security Symposium, USENIX Security 2018","author":"Poddebniak Damian","year":"2018","unstructured":"Damian Poddebniak, Christian Dresen, Jens M\u00fc ller, Fabian Ising, Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and J\u00f6 rg Schwenk. 2018. Efail: Breaking S\/MIME and OpenPGP Email Encryption using Exfiltration Channels. In 27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15--17, 2018, William Enck and Adrienne Porter Felt (Eds.). USENIX Association, 549--566. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/poddebniak"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1978.1055817"},{"key":"e_1_3_2_2_30_1","first-page":"918","article-title":"Monte Carlo methods for index computation mod p","volume":"32","author":"Pollard John M.","year":"1978","unstructured":"John M. Pollard. 1978. Monte Carlo methods for index computation mod p. Math. Comp., Vol. 32 (1978), 918--924.","journal-title":"Math. Comp."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.22667\/JOWUA.2020.09.30.107"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/0--387--34805-0_22"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1090\/pspum\/020\/0316385"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-009--9049-y"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/BFb0054019"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--642--23822--2_27"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/3--540--68339--9_29"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/PL00003816"},{"key":"e_1_3_2_2_39_1","volume-title":"Proceedings of the 23rd USENIX Security Symposium","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA, August 20--22, 2014, Kevin Fu and Jaeyeon Jung (Eds.). USENIX Association, 719--732. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/yarom"}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Virtual Event Republic of Korea","acronym":"CCS '21"},"container-title":["Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3485257","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3485257","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T20:49:57Z","timestamp":1763498997000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3485257"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,12]]},"references-count":39,"alternative-id":["10.1145\/3460120.3485257","10.1145\/3460120"],"URL":"https:\/\/doi.org\/10.1145\/3460120.3485257","relation":{},"subject":[],"published":{"date-parts":[[2021,11,12]]},"assertion":[{"value":"2021-11-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}