Question: Problem 2 . Committing encryption. A common mistake is to assume that encryption commits the encryptor to the encrypted message. Let ( E , D
Problem Committing encryption. A common mistake is to assume that encryption commits the encryptor to the encrypted message. Let be a cipher defined over Suppose Alice chooses some kinK and minM and publishes : This ciphertext is then stored in a system that prevents any modification to Later, Alice is asked to decrypt this by revealing her key We say that the encryption scheme is committing if Alice cannot produce a inK such that where and reject.
a Give a complete game based definition for committing encryption. Your game need only capture the commitment aspect of the scheme, not confidentiality. Hint: in your game, the challenger does nothing, and the attacker should output two keys and along with some other data.
b Let CTR denote counter mode encryption with a random IV with key space Let be a secure MAC with key space Let be the derived CTRthenMAC cipher whose key space is We know that provides authenticated encryption. Show that is not a committing encryption scheme.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
