Question: Let Pi = ( Gen , MAC, Verify ) be a secure MAC scheme with Gen ( 1 ^ n ) in { 0
Let Pi Gen MAC, Verify be a secure MAC scheme with Genn in n and MAC : ntimes nn ie the MAC scheme works with keys and messages of size n and returns a tag represented by a bitstring of size n
Let F : ntimes n n be a lengthpreserving pseudorandom function.
State whether each of the following PRF candidates is or is not a pseudorandom function. If yes, prove it; if not, show a distinguisher that succeeds with nonnegligible probability. Hint: to prove that some of these candidates are not PRFs it may be useful to assume the existence of MACs or PRFs with input and output of arbitrary size. Feel free to assume that such PRFs and MACs do exist, and pick the parameter sizes that are the most suitable to prove your result.
a Fk x MACknxn
b Fk x Fk xANDx
c Fk x MACFknnxn
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
