Question: A website authenticates its users by asking for a login / password , and sends them a cookie C , valid for one minute, to

A website authenticates its users by asking for a login/password, and sends them a cookie C, valid for one minute, to keep track of their authentication status. The cookie C is formed such as C = Enc("user=username,tmstmp=timestamp"), with username = "anonymous" for unauthenticated users, or the name of the user when authenticated; and timestamp is a Unix-formated timestamp1 representing the time up to which the user is authenticated (current time plus one minute). Enc() designates the AES256 encryption in OFB-mode using iv as a random IV and k as a random key; both k and iv are unknown to us. The OFB mode of operation for encryption is described in Figure 1.
In this exercise, we consider cookies delivered on February 1st,2024 at 00:00am UTC. At that time, an unauthenticated user coming to the website will receive a cookie

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!