Question: Alice is trying to decide between two different block ciphers, FOO and BAR, for her application. Both FOO and BAR have the same block size

Alice is trying to decide between two different block ciphers, FOO and BAR, for her application. Both FOO and BAR have the same block size and key length: {0, 1}n {0, 1}l {0, 1}l

Shes confident that at least one of them is secure, in that it doesnt have known vulnerabilities (beyond exhaustive key search), but isnt sure which of the two it is. As a hedge, she decides to combine them into a single new block cipher BAZ, that is also {0, 1}k {0, 1}l {0, 1}l and is defined for all x, y {0, 1}l and all K {0, 1}k as: BAZK(x) = FOOK(BARK(x)) BAZ1K (y) = BAR1K (FOO1K(y))

Alice finds its performance to be acceptable, but is BAZ a sound design from a security point of view? Find a convincing argument that BAZ can be insecure. (This can be shown even for the case when both blockciphers are secure.) Also, suggest a better design (no formal proof of security is required).

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!