Question: Consider a CBC-MAC and suppose that the encryption on key k1 (i.e., the last encryption block) is omitted. Show that such the MAC system is

Consider a CBC-MAC and suppose that the encryption on key k1 (i.e., the last encryption block) is omitted. Show that such the MAC system is not secure. Hint: Choose an arbitrary one-block message m E X, query the challenger for m and obtain its tag t = F(k,m). Now, find a two-block message m, such that t is a valid tag for m as well.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!