Download presentation
Presentation is loading. Please wait.
Published byMartin Skinner Modified over 9 years ago
1
1 CIS 5371 Cryptography 4. Message Authentication Codes B ased on: Jonathan Katz and Yehuda Lindell Introduction to Modern Cryptography
2
2 Message Authentication Codes
3
3 Definition 4.1 Message Authentication Code
4
4
5
5 Definition 4.2 -- Secure MAC
6
6 Construction 4.3 A fixed length MAC from any PRF
7
7 Theorem 4.4
8
8 A secure fixed length MAC Proof
9
9 Distinguisher D
10
10 Distinguisher D
11
11 Distinguisher D
12
12 Replay atta cks
13
13 Construction 4.5 A variable length MAC
14
14 Theorem 4.6
15
15 Construction 4.9 CBC- MAC
16
16 Theorem 4.10
17
17 CBC-MAC vs CBC-mode encryption 1.CBC-mode encryption uses a random IV. If we use a random IV for CBS-MAC then we lose security. 2.In CBC-mode encryption all encrypted blocks are output as part of the ciphertext. This is not the case with CBC-MAC. If we do so we loose security.
18
18 Secure CBC-MAC for variable length messages – three options
19
19 Variable length CBC-MAC
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.