Question: This exercise is from Introduction to Modern Cryptography (2nd Edition) by Katz & Lindell Consider defining a MAC by Mack (m)-H(? m) where H is
This exercise is from Introduction to Modern Cryptography (2nd Edition) by Katz & Lindell
Consider defining a MAC by Mack (m)-H"(? m) where H is a collision-resistant hash function. Show that this is not a secure MAC when H is constructed via the Merkle-Damgard transform. As usual, assume that the hash key s is publicly known
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
