Question: Let (E,D) be a CPA-secure cipher defined over (K,M,C) and let H: M-Tbe a collision-resistant hash function. Show that the following cipher is not AE-secure:

Let (E,D) be a CPA-secure cipher defined over (K,M,C) and let H: M-Tbe a collision-resistant hash function. Show that the following cipher is not AE-secure: E,(k,m) (E(k,m), H(m)- (c1, C2) D(k,c if H( D(k,c1)) C2 L (reject), otherwise Let (E,D) be a CPA-secure cipher defined over (K,M,C) and let H: M-Tbe a collision-resistant hash function. Show that the following cipher is not AE-secure: E,(k,m) (E(k,m), H(m)- (c1, C2) D(k,c if H( D(k,c1)) C2 L (reject), otherwise
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
