Question: 4. For any block cipher, the fact that it is a nonlinear function is crucial to its security. To see this, suppose that we have
4. For any block cipher, the fact that it is a nonlinear function is crucial to its security. To see this, suppose that we have a linear block cipher LIN that encrypts 128-bit blocks of plaintext into 128-bit blocks of ciphertext. Let LIN(k, m) denote the encryption of a 128-bit message m under a key k (the actual bit length of k is irrelevant). Thus LIN(k. [ mm2])-LIN(k, [m] LIN(k. [m2]) for all 128-bit patterns mi,m. Describe how, with 128 chosen ciphertexts, an adversary can decrypt any ciphertext without knowledge of the secret key k. (In a chosen ciphertext attack the adversary can choose any ciphertext and obtain its decryption. Here, you have 128 plaintext/ciphertext pairs to work with and you have the ability to choose the value of the ciphertexts.)
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
