Professional Documents
Culture Documents
A
fixed-‐length
MAC
Intui/on?
• We
need
a
keyed
func/on
Mac
such
that
– Given
Mack(m1),
Mack(m2),
…,
– …it
is
infeasible
to
predict
the
value
Mack(m)
for
any
m∉{m1,
…,
}
m1 m1
t1 t1
…
mi mi
PRF/random ti ti
m m, t
if
(t=t*)
t* output 1 D
Analysis
• When
D
interacts
with
Fk
for
uniform
k,
the
view
of
the
adversary
is
iden/cal
to
its
view
in
the
real
MAC
experiment
– Pr[DFk
outputs
1]
=
Pr[ForgeAdv,
Π(n)
=
1]