Question: Problem 1 : On leaking, or hiding, the message length Consider encryption scheme Gen, Enc, Dec ) that is EAV - secure w . r

Problem 1: On leaking, or hiding, the message length
Consider encryption scheme Gen, Enc, Dec) that is EAV-secure w.r.t. the definition in Figure 1.
Figure 1: Indistinguishability of encryptions in the presence of an eavesdropper.
(1) What does the condition |m0|=|m1| capture? Does it weaken or strengthen 's security?
(2) Let PrivK-EAV 2A,'(n) be the game in Figure 1 where A is allowed to choose challenge messages
of arbitrary length for breaking encryption scheme '=(Gen',Enc',Dec'), and consider the security
notion derived by this modified game: Intuitively, ' is EAV2-secure, if no efficient A can determine
cb better than guessing, even when |m0||m1|. Show that no EAV2-secure scheme ' exists.
Hint: First, note that ' is defined over message space M={0,1}**, i.e., messages of
arbitrary length. Then, assume that polynomial p(n) is an upper bound on the time
spent by Enc' for encrypting a single bit, and consider what happens when A chooses
m0in{0,1} and a random m1in{0,1}p(n)+c, where c1 a positive integer.
*** Please answer question number 2
 Problem 1: On leaking, or hiding, the message length Consider encryption

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!