For any choice of α∈ Zp, there is a unique choice of Φ(i) ∈ G for every i ∈ I such that ti is consistent with A's view. As Φ is truly random, A learns no information about α from ek even if it is computationally unbounded (such that computing discrete logarithms is easy...