Question: Consider a raw CBC MAC construction from Lecture 6, part 1 (marked in green on slide 24 it uses only one key k). a) Show
Consider a raw CBC MAC construction from Lecture 6, part 1 (marked in green on slide 24 it uses only one key k).
a) Show that prepending the message with its length denoted |m| (i.e., adding an extra block before m[0] with |m| encoded in binary) results in a secure MAC.
b) Show that appending |m| to the end of the message does not result in a secure MAC.

raw CBC with pre-pended message length m[O) m[2] F(k,) F(k,) tag raw CBC with pre-pended message length m[O) m[2] F(k,) F(k,) tag
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
