Recall the encryption mode CBC$ we studied in class. The scheme uses a random IV and...
Fantastic news! We've Found the answer you've been seeking!
Question:
Transcribed Image Text:
Recall the encryption mode CBC$ we studied in class. The scheme uses a random IV and is based on a blockcipher E. In class we saw that CBC$ is IND-CPA assuming E is a PRF, and it is never IND-CCA. Your colleague suggests the following encryption scheme CBCH in an effort to make it IND-CCA. The only difference is that in place of IV the encryption algorithm uses H(M), where H is a public, keyless hash with n-bit outputs and M is the message to encrypt. The decryption algorithm decrypts M as usual but also checks that the IV is H(M). If not, it rejects and outputs L. The colleague claims that CBCH is IND-CCA assuming E is a PRF. Show that the colleague is wrong and prove that CBCH is not IND-CCA secure. Recall the encryption mode CBC$ we studied in class. The scheme uses a random IV and is based on a blockcipher E. In class we saw that CBC$ is IND-CPA assuming E is a PRF, and it is never IND-CCA. Your colleague suggests the following encryption scheme CBCH in an effort to make it IND-CCA. The only difference is that in place of IV the encryption algorithm uses H(M), where H is a public, keyless hash with n-bit outputs and M is the message to encrypt. The decryption algorithm decrypts M as usual but also checks that the IV is H(M). If not, it rejects and outputs L. The colleague claims that CBCH is IND-CCA assuming E is a PRF. Show that the colleague is wrong and prove that CBCH is not IND-CCA secure.
Expert Answer:
Answer rating: 100% (QA)
ANSWER The colleagues suggestion CBCH is not INDCCA secure because it is vulnerable to a chosen ciphertext attack In this attack the adversary can choose a message M and a corresponding IV HM and then ... View the full answer
Related Book For
A Concise Introduction to Logic
ISBN: 978-1305958098
13th edition
Authors: Patrick J. Hurley, Lori Watson
Posted Date:
Students also viewed these programming questions
-
A sphere made from material [Cast Iron] has a radius of [45] mm at a temperature of 20C and has the coefficient of linear expansion (a) is [10x10] per C. Then the temperature of the sphere is raised...
-
The Crazy Eddie fraud may appear smaller and gentler than the massive billion-dollar frauds exposed in recent times, such as Bernie Madoffs Ponzi scheme, frauds in the subprime mortgage market, the...
-
Planning is one of the most important management functions in any business. A front office managers first step in planning should involve determine the departments goals. Planning also includes...
-
Examine how effective change communication can reduce resistance in organization ? explain
-
Use a linear interpolation to estimate properties of ammonia to fill out the table below P [kPa] T [ C] v [m3/kg] x a) 550 0.75 b) 80 20 c) 10 0.4
-
On November 1, 2005, Janet Morton and Kim Wong formed Pet Kingdom, Inc., to sell pets and pet supplies. Pertinent information regarding Pet Kingdom is summarized as follows: Pet Kingdom's business...
-
In a domestic refrigerator, the refrigerant commonly used is (a) Air (b) Carbon dioxide (c) Ammonia (d) Freon-12
-
Haversham Corporation produces dress shirts. The company uses a standard costing system and has set the following standards for direct materials and direct labor (for one shirt): Fabric (1.5 yds. @...
-
Anderson Corporation has found that 80% of its sales in any given month are credit sales, while the remainder are cash sales. Of the credit sales, Anderson Corporation has experienced the following...
-
A four-year financial project has estimates of net cash flows shown in the following table: It will cost $65,000 to implement the project, all of which must be invested at the beginning of the...
-
Which of the following processes will a computer assembling firm engage in if it decides to manufacture its own monitors and printers? A) lean production B) vertical integration C) niche marketing D)...
-
National parks to offer free-entry weekends Interior Secretary Ken Salazar has urged everyone to visit the national parks over the weekends of June 20-21, July 18-19, and August 15-16 when admission...
-
Oskar's Odditorium sells fidget spinners. Oskar estimates the price elasticity of demand for fidget spinners is 1.2. If Oskar wants to increase sales by 15 percent and assuming no change (i.e., no...
-
How is the act of Projection at play in how the narrator uses the Old Man/how he perceives his Evil Eye to maintain the sense of self, the Persona , he is compulsively beholden to? Consider the...
-
Describe the strategic implications of self-driving cars or robotics on traditional companies.
-
How is HR Planning linked to a companys strategic goals? If a company is expecting 50% growth per year for 3 years, how can trend analysis be used to determine HR demand? Is ration analysis helpful...
-
Assuming that interest is 16% compounded quarterly, which amount is worth more: MWK 10,000.00 today or a 5 year annuity of MWK1000.00 each quarter
-
Assume that your audit team has established the following parameters for the examination of ELM's sales transactions: LO G-3 Risk of incorrect acceptance...
-
If Maria Cantwell promotes alternative energy, then if Patty Murray supports wilderness areas, then Dianne Feinsteins advocating gun control implies that Susan Collins does so, too. Translate the...
-
Use the first eight rules of inference to derive the conclusions of the following symbolized arguments:
-
Use either indirect proof or conditional proof to derive the conclusions of the following symbolized arguments.
-
With reference to Exercise 11.65, (a) find a \(99 \%\) confidence interval for the mean battery backup at \(x=1.25\); (b) find \(95 \%\) limits of prediction for the battery backup provided by a...
-
A chemical engineer found that by adding different amounts of an additive to gasoline, she could reduce the amount of nitrous oxides (NOx) coming from an automobile engine. A specified amount was...
-
To determine how well existing chemical analyses can detect lead in test specimens in water, a civil engineer submits specimens spiked with known concentrations of lead to a laboratory. The chemists...
Study smarter with the SolutionInn App