Question: ( b ) Let G : { , 1 } { , 1 } + l be a candidate PRG . Suppose there is a
b Let : be a candidate PRG Suppose there is a polynomialtime
algorithm with the property that it inverts with nonnegligible probability. That
is
nonnegligible.
Show that if an algorithm exists with this property, then is not a secure PRG In
other words, construct a distinguisher contradicting the PRGsecurity of and show
that it achieves nonnegligible distinguishing advantage.
Note: Don't assume anything about the output of other than the property shown
above. In particular, might very frequently output the "wrong" thing.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
