You are on page 1of 11

02

1.5 2021
Lectured
PRG PRF
SKI IND EAV IND CPA IND CCA AE

MAC
Mini crypt ONE exists

GographeHashfinction
Gen H
Pair of PPT algorithms

Get s GenCin

Hash 17 0,13 7 on

ne 0,13 h H n

la
If Hs 0,13dm o i

fixed length hash


Compresrofction
een
Compression In
Collision Resistance
IT Gen H
Hash colla.pl
A wins if
Mo m and

mpg F1 HS Mo HS Mi

is Collision Resistant if PPT A


IT

F negeen 7
2 a
I neglens
Pr Hash colla

weakerNoting
as 0,1354011

É c 0.13
t

A if m m and H Cm H em
Lins
Is 015 onsen

Beings
9 9131,1
one way function
7 Hsc p y t
easy to compute
Hard to Invert

6 fpre.im
ondPr Resistance

IT is S Preimage
If IT is CR
which
F PPT It which can F PPT B
Hash coll
s preimage breaks
a
find
t
typo
HT 0.11 on

1 me
m

4121
m

MBA L

IYITI.IT em

If Gen h is CR then Gen HJ is

also CRT
Mae L
M

IE
Et

Mo Mi
AI HIM
Imo Mil
I I
L Il ZB 1211 ZB
LIEB
hs 411 ZB IL
É IMol IMI HS Mo H'CMD

Mo Mr y j
Ijm
In Practice
constr E
III.TT cksn
QN
Fk n

DavidMstution
Then use MD transform

M's
1,1
SHA

SHA 3 keek
IIIEII.in
Fe Ffixed ength mac
CGmn

T
Gen
Gent k 0,13ns
K Kis

MAI Is MACKCHSCMI

vote is

I
m t k 1
Vofy H
J

IT is a secure fixed length MAC


If is secure
and TH is a CR then I a

MAC
t MACK
Igm
FEITH
I
t
fixed length CRH Mj w

Mit l
mac A wins if Vrfy
and m Q
and
If II is secure fixed length MAC
is isseamem
It
FA
F PPT A agonist I 7 ppt B that breaks
TIN
or PPTB that breaks

Card m t Q HS mA HS m

m m
t
Breaks the CR of Hs

Hm H mt H em
Caself E Q

then that is a valid forgery agonist the


Fixed length MAC
memento before
The Reduction can see se

extractability

PEE HIP
Program H
Reduction can
Programmability

H Kum
MAG Klm is
t
MAC in RO model
Secure e

instantiated
Not secure if
with MD Transform
GeyicattackonHashfunction
e
Iven A 0,13 3 on

Fone I

F Mi Mj 7 HS mi H mi

there is a collision
Probability 1
D
2 s Rq
Compute bit H Cri
Yi Yj for
then check for collision
some
Ki Nj

l
ME Fix N q elements y you
are chosen uniformly End independently
at random fronasetafsize
e

Pr Icon I 2dg
A

Po Coll Pr Yycolli

Element collide with the


Colli the ith
element
jth

Pr Colli
In Conard
Colli
P Coll Pr
y
Pr Icolli E I
Ig En

You might also like