Question: Let E {0, 1} {0,1} {0,1} be a secure blockcipher. Consider the following deterministic MAC scheme ({0, 1), T, V) with the message space

Let E {0, 1} {0,1}" {0,1}" be a secure blockcipher. Consider the following deterministic MAC scheme ({0, 1), 

Let E {0, 1} {0,1}" {0,1}" be a secure blockcipher. Consider the following deterministic MAC scheme ({0, 1), T, V) with the message space of messages longer than n bits. The tagging algorithm T is defined as: T(K, M) = E(K, M) || M where M is the first n bits of M and M is the rest. The verification algorithm just re-computes the tagging algorithm. Prove that this MAC is not UF-CMA.

Step by Step Solution

3.42 Rating (155 Votes )

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock

In order to prove that the given MAC scheme is not UFCMA Unforgeable under ChosenMessage Attack we n... View full answer

blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!