Question: Let F be a secure PRF , and let m in { 0 , 1 } in be a fixed ( therefore known to the

Let F be a secure PRF, and let m in {0,1}in be a fixed (therefore known to the adversary) string. Define the new function
Fm(k,x)= F(k,x) F(k,m).
Show that Fm is not a secure PRF. Describe a distinguisher and compute its advantage.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!