Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Problem 2 . Committing encryption. A common mistake is to assume that encryption commits the encryptor to the encrypted message. Let ( E , D
Problem Committing encryption. A common mistake is to assume that encryption commits the encryptor to the encrypted message. Let ED be a cipher defined over KMC Suppose Alice chooses some k in K and m in M and publishes c : Ekm This ciphertext c is then stored in a system that prevents any modification to c Later, Alice is asked to decrypt this c by revealing her key k We say that the encryption scheme is committing if Alice cannot produce a k in K such that Dkc m where m m and m reject.
a Give a complete game based definition for committing encryption. Your game need only capture the commitment aspect of the scheme, not confidentiality. Hint: in your game, the challenger does nothing, and the attacker should output two keys k and k along with some other data.
b Let CTR denote counter mode encryption with a random IV with key space Ke Let S V be a secure MAC with key space Km Let ED be the derived CTRthenMAC cipher whosekeyspaceisKetimes Km WeknowthatEDprovidesauthenticatedencryption Show that ED is not a committing encryption scheme.
Problem Committing encryption. A common mistake is to assume that encryption commits the encryptor to the encrypted message. Let ED be a cipher defined over KMC Suppose Alice chooses some k in K and m in M and publishes c : Ekm This ciphertext c is then stored in a system that prevents any modification to c Later, Alice is asked to decrypt this c by revealing her key k We say that the encryption scheme is committing if Alice cannot produce a k in K such that Dkc m where m m and m reject.
a Give a complete game based definition for committing encryption. Your game need only capture the commitment aspect of the scheme, not confidentiality. Hint: in your game, the challenger does nothing, and the attacker should output two keys k and k along with some other data.
b Let CTR denote counter mode encryption with a random IV with key space Ke Let S V be a secure MAC with key space Km Let ED be the derived CTRthenMAC cipher whosekeyspaceisKetimes Km WeknowthatEDprovidesauthenticatedencryption Show that ED is not a committing encryption scheme.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started