1 of 14

Lecture 12: Encryption Schemes (V)

2 of 14

  • EAV-security: adversary observes ciphertext
  • CPA-security: adversary observes (message, ciphertext) pairs
  • What if adversary can modify ciphertext transmitted?

  • This is the setting of MAC
    • MAC guarantees message integrity, doesn’t care about secrecy
    • What if we want both?

 

 

???

3 of 14

Chosen-Ciphertext Attacks

4 of 14

  •  

 

 

 

 

5 of 14

CCA-security

  •  
  •  

 

6 of 14

  •  
  •  

 

7 of 14

Previous CPA-secure encryption scheme is not CCA-secure…

  •  

8 of 14

  •  

9 of 14

  •  

10 of 14

CCA-Secure Encryption Scheme

11 of 14

Encrypt-then-MAC

  •  

12 of 14

  •  

13 of 14

  •  

message

tag

 

 

ciphertext

14 of 14

  •  

message

tag

 

 

ciphertext