Question: Let F be a pseudorandom function. Show that the following MAC for messages of length 2n is insecure: Gen outputs a uniform k {0, 1}
Let F be a pseudorandom function. Show that the following MAC for messages of length 2n is insecure: Gen outputs a uniform k {0, 1} n. To authenticate a message m1km2 with |m1| = |m2| = n, compute the tag Fk(m1) k Fk(Fk(m2)).
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
