Question: 6 . 4 . Let F be a secure PRF with in = 2 , and let G be a length - doubling PRG .
Let be a secure PRF with in and let be a lengthdoubling PRG Define
We will see that is not necessarily a PRF
a Prove that if is injective then is a secure PRF
b Exercise b constructs a secure lengthdoubling PRG that ignores half of its input.
Show that is insecure when instantiated with such a PRG Give a distinguisher and
compute its advantage.
Note: You are not attacking the PRF security of nor the PRG security of You are
attacking the invalid way in which they have been combined.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
