Question: ( b ) Let G : { , 1 } { , 1 } + l be a candidate PRG . Suppose there is a

(b) Let G:{,1}{,1}+l be a candidate PRG. Suppose there is a polynomial-time
algorithm V with the property that it inverts G with non-negligible probability. That
is,
Prslarr{[,1}[V(G(s))=s]is non-negligible.
Show that if an algorithm V exists with this property, then G is not a secure PRG. In
other words, construct a distinguisher contradicting the PRG-security of G and show
that it achieves non-negligible distinguishing advantage.
Note: Don't assume anything about the output of V other than the property shown
above. In particular, V might very frequently output the "wrong" thing.
 (b) Let G:{,1}{,1}+l be a candidate PRG. Suppose there is a

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!