Lecture 7: Message Authentication Codes (IV)
Recap: Secure MAC scheme
Security proof
Putting it together
Recap 1: Hybrid argument
intermediate game
original game
Recap 2: Use random function instead of PRF
Recap 3: Proof by reduction
Variable-Length MAC Schemes
Attempt 1
Attempt 2
Secure variable-length MAC scheme 1:�Hash-then-MAC
message
compressed message
tag
Secure variable-length MAC scheme 2:�CBC-MAC