Question: Prove that the following modications of basic CBC-MAC do not yield a secure MAC (even for xed-length messages): (a) Mac outputs all blocks t1,...,t`, rather
Prove that the following modications of basic CBC-MAC do not yield a secure MAC (even for xed-length messages): (a) Mac outputs all blocks t1,...,t`, rather than just t`. (Verication only checks whether t` is correct.)
hint: the attack has oracel access to the MAC (training phase) to get a message and tag pair, then needs to output/find another pair to pass Vrfy, or find a different message with the same tag as the one in training phase.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
