Question: Solutions must be typed and submitted electronically. 1. Suppose Enc-then-MAC +AD is instantiated with CBC mode and any secure MAC, as described in the text.
Solutions must be typed and submitted electronically. 1. Suppose Enc-then-MAC +AD is instantiated with CBC mode and any secure MAC, as described in the text. The scheme is secure for fixed-length associated data. Show that if variable-length associated data is allowed, then the scheme does not provide AEAD security. Note: you are not attacking the MACl Take advantage of the fact that dc is ambiguous when the length of d is not fixed and publicly known. For reference: this question is refering to the AEAD security (definition 15.2 in the book) of this scheme: The set of associated data signifiers is D={0,1}
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
