Question: A website authenticates its users by asking for a login / password , and sends them a cookie C , valid for one minute, to
A website authenticates its users by asking for a loginpassword and sends them a cookie C valid for one minute, to keep track of their authentication status. The cookie C is formed such as C Encuserusername,tmstmptimestamp" with username "anonymous" for unauthenticated users, or the name of the user when authenticated; and timestamp is a Unixformated timestamp representing the time up to which the user is authenticated current time plus one minute Enc designates the AES encryption in OFBmode using iv as a random IV and k as a random key; both k and iv are unknown to us The OFB mode of operation for encryption is described in Figure
In this exercise, we consider cookies delivered on February st at :am UTC. At that time, an unauthenticated user coming to the website will receive a cookie
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
