Fix a symmetric-key encryption scheme SE (K, E, D). We consider alternative notions of security to...
Fantastic news! We've Found the answer you've been seeking!
Question:
Transcribed Image Text:
Fix a symmetric-key encryption scheme SE (K, E, D). We consider alternative notions of security to IND-CPA below. First consider the MROR (message real-or- random) notion via game MRoR-1 below left and MROR-0 below right. proe INITIALIZE K+K proc RoR(m) Return E (m) Define the MROR-advantage of A against SE as Adve (A) = Pr [MROR-1 outputs 1] - Pr [MROR-0 outputs 1]. proc INITIALIZE KIK proc INITIALIZE K-sk Now consider the CROR (ciphertext real-or-random) notion via game CROR-1 below left and CROR-0 below right. proe RoR(m) Return Ex(m) proc ROR(m) m's {0, 1] Return Ex(m) Define the CROR-advantage of A against. SE as proc INITIALIZE K-K proc ROR(m) ex Ek(m) {0, 134 Return Adve (4) Pr [CROR-15 outputs 1] Pr [CROR-05 outputs 1]. (Part A.). Show that IND-CPA implies MROR. Namely, show that for every MROR-adversary A there is an IND-CPA adversary B such that indepa SE Furthermore, the resources usage of B is about that of A. Adv (A) Adv (B). uror (Part B.). Show that MROR implies IND-CPA. Namely, show that for every IND-CPA adversary A there is an MROR-adversary B such that Advse ind-cpa Furthermore, the resources usage of B is about that of A. (A) 2. Adv (B). mror SE Show IND-CPA does not imply CROR. To show this, assume there is a scheme SE (K, E, D) that is IND-CPA (as otherwise the claim is vacuous). Show how to modify SE into SE' = (K',E, D) such that: (1) SE' is IND-CPA but (2) SE' is not CROR. Namely, first provide a description of the algorithms of SE'. Then show that for every IND-CPA adversary A there is an IND-CPCA adversary B such that Adv SE' (A) Adv (B). SE Furthermore, the resources usage of B is about that of A. Finally, show that there is a resource- efficient CROR-adversary A such that Adv (A) 2 1 1 Fix a symmetric-key encryption scheme SE (K, E, D). We consider alternative notions of security to IND-CPA below. First consider the MROR (message real-or- random) notion via game MRoR-1 below left and MROR-0 below right. proe INITIALIZE K+K proc RoR(m) Return E (m) Define the MROR-advantage of A against SE as Adve (A) = Pr [MROR-1 outputs 1] - Pr [MROR-0 outputs 1]. proc INITIALIZE KIK proc INITIALIZE K-sk Now consider the CROR (ciphertext real-or-random) notion via game CROR-1 below left and CROR-0 below right. proe RoR(m) Return Ex(m) proc ROR(m) m's {0, 1] Return Ex(m) Define the CROR-advantage of A against. SE as proc INITIALIZE K-K proc ROR(m) ex Ek(m) {0, 134 Return Adve (4) Pr [CROR-15 outputs 1] Pr [CROR-05 outputs 1]. (Part A.). Show that IND-CPA implies MROR. Namely, show that for every MROR-adversary A there is an IND-CPA adversary B such that indepa SE Furthermore, the resources usage of B is about that of A. Adv (A) Adv (B). uror (Part B.). Show that MROR implies IND-CPA. Namely, show that for every IND-CPA adversary A there is an MROR-adversary B such that Advse ind-cpa Furthermore, the resources usage of B is about that of A. (A) 2. Adv (B). mror SE Show IND-CPA does not imply CROR. To show this, assume there is a scheme SE (K, E, D) that is IND-CPA (as otherwise the claim is vacuous). Show how to modify SE into SE' = (K',E, D) such that: (1) SE' is IND-CPA but (2) SE' is not CROR. Namely, first provide a description of the algorithms of SE'. Then show that for every IND-CPA adversary A there is an IND-CPCA adversary B such that Adv SE' (A) Adv (B). SE Furthermore, the resources usage of B is about that of A. Finally, show that there is a resource- efficient CROR-adversary A such that Adv (A) 2 1 1
Expert Answer:
Answer rating: 100% (QA)
Part A Showing that INDCPA implies MROR To prove this we need to show that for every MRORadversary A there exists an INDCPA adversary B such that AdvA AdvB and the resource usage of B is about that of ... View the full answer
Related Book For
Income Tax Fundamentals 2013
ISBN: 9781285586618
31st Edition
Authors: Gerald E. Whittenburg, Martha Altus Buller, Steven L Gill
Posted Date:
Students also viewed these programming questions
-
Divide 8(cos0.8 + i sin0.8) by 4(cos0.2 + i sin0.2).
-
The following additional information is available for the Dr. Ivan and Irene Incisor family from Chapters 1-5. Ivan's grandfather died and left a portfolio of municipal bonds. In 2012, they pay Ivan...
-
Planning is one of the most important management functions in any business. A front office managers first step in planning should involve determine the departments goals. Planning also includes...
-
Mr. Mo carries on business as a sole proprietor. The fiscal year end of the business is December 31. During 2020, its first year of operation, net business loss amounts to $72,000. In addition, the...
-
A pulse traveling along a string of linear mass density is described by the wave function y = [A0ebx] sin (kx wt) Where the factor in brackets before the sine function is said to be the amplitude (a)...
-
The Costa Rican Coffee Company is evaluating the within-plant distribution system for its new roasting, grinding, and packing plant. The two alternatives are (1) a conveyor system with a high initial...
-
Commercial airliners normally cruise at relatively high altitudes \((30,000\) to \(35,000 \mathrm{ft}\) ). Discuss how flying at this high altitude (rather than 10,000 ft, for example) can save fuel...
-
Gateway Tours is choosing between two bus models. One is more expensive to purchase and maintain, but lasts much longer than the other. Its discount rate is 11%. It plans to continue with one of the...
-
Jul 4, 2024: Recorded credit card sales of $110,000, net processor fee of 1% Ignore cost of Goods sold. (Prepare a single compound journal entry.) Date Jul. 1 Accounts and Explanation Debit Credit...
-
Three employees of the Horizon Distributing Company will receive annual pension payments from the company when they retire. The employees will receive their annual payments for as long as they live....
-
Statistical calculations and preparation of tables and graphs can be done using O Excel O QBASIC O word 2 points
-
Compute the present value of annual cash payments of $200 per year, for 4 years, using a discount rate of 5%.
-
Starting at rest, a hydroplane accelerates at a = 0.8t for the first 10 seconds and then accelerates at a = -1.2t + 20 until it comes to a stop. The acceleration is show on the graph below. a (m/s^2)...
-
An investor purchased an equity fund several years ago at a total cost of $5,000 and sold it this year receiving $12,500 in total proceeds. During the holding period, capital gains distributions of...
-
Ernie receives all the stock of EBU Company in exchange for contributing a machine with a basis of $15,000 and an FMV of $25,000. Ernie also receives $3,000 cash from the company. The gain on...
-
at the end of the year accounts receivable has a balance of $ 4 3 7 5 0 0 0 : allowance for Doubtful Accounts has a debit balance of $ 2 1 3 0 0 : and sales for the year total $ 1 0 2 4 8 0 0 0 0 ....
-
Q.12 A polynomial of least degree such that lim 1+ -x2 + 2x2 -x2 + 2x3 x3 + 2x2 l/x f(x) liay 1 + 2 + (2) " = None of these =e is
-
(a) Given a mean free path = 0.4 nm and a mean speed vav = 1.17 105 m/s for the current flow in copper at a temperature of 300 K, calculate the classical value for the resistivity of copper. (b)...
-
Ray and Maria Gomez have been married 3 years. They live at 1610 Quince Ave., McAllen, TX 78701. Ray works for Palm Oil Corporation and Maria works for the City of McAllen. Maria's Social Security...
-
Jerry made the following contributions during 2012: His synagogue (by check).....................................................$680 The Democratic Party (by check)...
-
William sold Section 1245 property for $25,000 in 2012. The property cost $35,000 when it was purchased 5 years ago. The depreciation claimed on the property was $16,000. a. Calculate the adjusted...
-
What is an overnight reverse repurchase agreement (ON RRP)? What role does the interest on ON RRP play in the way the Fed hits its target for the federal funds rate in the current ample-reserves...
-
A Federal Reserve publication observed that today, the The Feds primary tool for adjusting the federal funds rate is interest on reserve balances. a. Briefly explain the reasoning behind this...
-
In the following graph of the federal funds market, briefly explain whether the banking system is in a scarce reserves regime or an ample-reserves regime. In this situation, briefly explain whether...
Study smarter with the SolutionInn App