Question: 6 . 8 . Suppose F is a secure P R F with input length in , but we want to use it to construct

6.8. Suppose F is a secure PRF with input length in, but we want to use it to construct a PRF
with longer input length. Below are some approaches that don't work. For each one,
describe a successful distinguishing attack and compute its advantage:
(a)F'(k,x||x')=F(k,x)||F(k,x'), where x and x' are each in bits long.
(b)F'(k,x||x')=F(k,x)o+F(k,x'), where x and x' are each in bits long.
(c)F'(k,x||x')=F(k,x)o+F(k,xo+x'), where x and x' are each in bits long.
(d)F'(k,x||x')=F(k,0||x)o+F(k,1||x'), where x and x' are each in -1 bits long.
 6.8. Suppose F is a secure PRF with input length in,

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!