Back to Library
QID: #28301
Solution for QID #28301: Turns out that the company from Problem 2 hired a cryptograp | StudyHelpMe
Turns out that the company from Problem 2 hired a cryptography consultant
to assess security of the encryption scheme S E ′
(described in Problem 2). The consultant concluded that S E ′
is IND-CCA assuming the base scheme S E
is IND-CCA and justified her statement with the following.
For any efficient IND-CCA adversary A attacking S E ′
, we construct an efficient IND-CCA adversary B attacking S E
as follows:
Adversary B is given the LR oracle and the Decryption oracle. It runs adversary A.
For every A's LR encryption query (M0,M1), B parses M0 as two halves M0[1] || M0[2],
parses M1 as two halves M1[1] || M1[2] and queries its LR oracle twice,
first on (M0[1],M1[1]), and then on (M0[2],M1[2]). Let us call responses of the oracle for these two queries C and C'. Then it returns to A ciphertext C || C'.
For every A's decryption query C[1] || C[2], B queries its own decryption oracle first on C[1], and then on C[2], and returns to A the concatenation of the oracles's responses.
When A outputs a bit, B outputs the same bit.
Analyzing the above construction we see that B's ind-cca advantage is the same as A's ind-cca advantage because the simulation is perfect, i.e., A's view in the experiment simulated by B is exactly like in its IND-CCA experiment; and B wins whenever A wins.
Clearly, B is efficient whenever A is efficient: t(B) ≈
t(A), qe(B)=2qe(A), qd(B)=2qd(A), μ
e(B)=μ
e(A), μ
d(B)=μ
d(A).
Find a serious mistake in the above "proof". A couple of sentences should be enough for the solution here. Finding an attack on the scheme is not what the question is about, this is the goal of Problem 2.
ZERO AI
Human Written
Human Written
PHD EXPERTS
Verified
Verified
TURNITIN
Clean Report
Clean Report
FAST DELIVERY
Instant/Hourly
Instant/Hourly