Question: ( 2 ) Let PrivK - EAV 2 A , Pi 0 ( n ) be the game in Figure 1 where A is

(2) Let PrivK-EAV2A,\Pi 0(n) be the game in Figure 1 where A is allowed to choose challenge messages of arbitrary length for breaking encryption scheme \Pi ), and consider the security notion derived by this modified game: Intuitively, \Pi 0 is EAV2-secure, if no efficient A can determine cb better than guessing, even when |m0|6=|m1|. Show that no EAV2-secure scheme \Pi 0 exists.
Hint: First, note that \Pi 0 is defined over message space M ={0,1}, i.e., messages of arbitrary length. Then, assume that polynomial p(n) is an upper bound on the time spent by Enc0 for encrypting a single bit, and consider what happens when A chooses m0 in {0,1} and a random m1 in {0,1}p(n)+c, where c >=1 a positive integer.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!