Question: Recall the encryption mode CBC$ we studied in class. The scheme uses a random IV and is based on a blockcipher E. In class

Recall the encryption mode CBC$ we studied in class. The scheme uses a random IV and is based on a

Recall the encryption mode CBC$ we studied in class. The scheme uses a random IV and is based on a blockcipher E. In class we saw that CBC$ is IND-CPA assuming E is a PRF, and it is never IND-CCA. Your colleague suggests the following encryption scheme CBCH in an effort to make it IND-CCA. The only difference is that in place of IV the encryption algorithm uses H(M), where H is a public, keyless hash with n-bit outputs and M is the message to encrypt. The decryption algorithm decrypts M as usual but also checks that the IV is H(M). If not, it rejects and outputs L. The colleague claims that CBCH is IND-CCA assuming E is a PRF. Show that the colleague is wrong and prove that CBCH is not IND-CCA secure.

Step by Step Solution

3.39 Rating (152 Votes )

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock

ANSWER The colleagues suggestion CBCH is not INDCCA secure because it is vulnerable to a chosen ciphertext attack In this attack the adversary can choose a message M and a corresponding IV HM and then ... View full answer

blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!