Question: Let F be a secure block cipher and consider instantiating Enc - then - MAC with: our favorite CPA - secure encryption Enc ( k

Let F be a secure block cipher and consider instantiating Enc-then-MAC with: our favorite CPA-secure encryption Enc(k,m)=(r,F(k,r)m).- CBC-MAC restricted to 2-block inputs (construction 10.5) The encryption scheme is CPA-secure and the MAC is also a secure MAC since it is used on inputs of only 2 blocks (ciphertexts of the encryption scheme). Because of this Enc-then-MAC will result in a CCA-secure scheme. Show that the result is not CCA-secure when the same key (and same F ) is used for both the encryption \& MAC!

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!