❳❖❘ ♦❢ P❘Ps ✐♥ ❛ ◗✉❛♥t✉♠ ❲♦r❧❞
❇❛rt ▼❡♥♥✐♥❦✱ ❆❧❛♥ ❙③❡♣✐❡♥✐❡❝ ❘❛❞❜♦✉❞ ❯♥✐✈❡rs✐t② ✭❚❤❡ ◆❡t❤❡r❧❛♥❞s✮✱ ❑❯ ▲❡✉✈❡♥ ✭❇❡❧❣✐✉♠✮
P◗❈r②♣t♦ ✷✵✶✼ ❏✉♥❡ ✷✻✱ ✷✵✶✼
✶ ✴ ✶✼
PPs t r rt - - PowerPoint PPT Presentation
PPs t r rt rst trs
✶ ✴ ✶✼
✷ ✴ ✶✼
✷ ✴ ✶✼
✷ ✴ ✶✼
✸ ✴ ✶✼
CTR[E](q, t) ≤ Advprp E (q, t) +
✸ ✴ ✶✼
CTR[E](q, t) ≤ Advprp E (q, t) +
✸ ✴ ✶✼
✹ ✴ ✶✼
CTR[F](q) ≤ Advprf F (q)
✹ ✴ ✶✼
CTR[F](q) ≤ Advprf F (q)
✹ ✴ ✶✼
✺ ✴ ✶✼
✺ ✴ ✶✼
XoP(q, t) ≤ r · Advprp E (q, t) + q/2n
✺ ✴ ✶✼
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](q, t) ≤ Advprf XoP(q, t)
✻ ✴ ✶✼
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](q, t) ≤ Advprf XoP(q, t)
E (2q, t) + q/2n
✻ ✴ ✶✼
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](q, t) ≤ Advprf XoP(q, t)
E (2q, t) + q/2n
✻ ✴ ✶✼
✼ ✴ ✶✼
✼ ✴ ✶✼
✼ ✴ ✶✼
✼ ✴ ✶✼
✽ ✴ ✶✼
✽ ✴ ✶✼
✽ ✴ ✶✼
scheme based on primitive random function
SPk(q, t)
✾ ✴ ✶✼
scheme based on primitive random function
SPk(q, t)
✾ ✴ ✶✼
scheme based on primitive random function
SPk(q, t)
✾ ✴ ✶✼
✶✵ ✴ ✶✼
✶✵ ✴ ✶✼
✶✵ ✴ ✶✼
✶✵ ✴ ✶✼
scheme based on primitive random function
SPk(q, t)
✶✶ ✴ ✶✼
scheme based on ideal random function
SPk(q, t) ≤ Adv I Pk(q′, t′) + AdvR SI(q, t)
✶✶ ✴ ✶✼
scheme based on ideal random function
SPk(q, t) ≤ Adv I Pk(q′, t′) + AdvR SI(q, t)
Pk(q′, t′) +
✶✶ ✴ ✶✼
scheme based on ideal random function
SPk(q, t) ≤ Adv I Pk(q′, t′) + AdvR SI(q, t)
Pk(q′, t′) + AdvR SI(q, ∞)
✶✶ ✴ ✶✼
scheme based on primitive random function
SPk(q, ˆ
Pk(q′, ˆ
SI(q, ∞)
✶✷ ✴ ✶✼
scheme based on primitive random function
SPk(q, ˆ
Pk(q′, ˆ
SI(q, ∞)
✶✷ ✴ ✶✼
scheme based on primitive random function
SPk(q, ˆ
Pk(q′, ˆ
SI(q, ∞)
✶✷ ✴ ✶✼
scheme based on primitive random function
SPk(q, ˆ
Pk(q′, ˆ
SI(q, ∞)
✶✷ ✴ ✶✼
x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
XoPr(q, t) ≤ r · Advprp E (q, t) + q/2n
✶✸ ✴ ✶✼
x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
XoPr(q, t) ≤ r · Advprp E (q, t) + q/2n
XoPr(q, ˆ
E (q, ˆ
✶✸ ✴ ✶✼
x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
XoPr(τ, ˆ
✶✹ ✴ ✶✼
x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
XoPr(τ, ˆ
✶✹ ✴ ✶✼
✶✺ ✴ ✶✼
Z X Y g f
✶✺ ✴ ✶✼
Z X Y g f
✶✺ ✴ ✶✼
Z X Y g f
✶✺ ✴ ✶✼
Z X Y g f
✶ ◗✉❡r② ❳♦Pr(k, 1) = z1
✷ ❉❡✜♥❡ f(l) = El(1)
✸ ❆♣♣❧② ❚❛♥✐✬s ❛❧❣♦r✐t❤♠ t♦ ✜♥❞
✶✻ ✴ ✶✼ x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
✶ ◗✉❡r② ❳♦Pr(k, 1) = z1
✷ ❉❡✜♥❡ f(l) = El(1)
✸ ❆♣♣❧② ❚❛♥✐✬s ❛❧❣♦r✐t❤♠ t♦ ✜♥❞ l1, . . . , lr−1, m s✳t✳
✶✻ ✴ ✶✼ x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
✶ ◗✉❡r② ❳♦Pr(k, 1) = z1
✷ ❉❡✜♥❡ f(l) = El(1)
✸ ❆♣♣❧② ❚❛♥✐✬s ❛❧❣♦r✐t❤♠ t♦ ✜♥❞ l1, . . . , lr−1, m s✳t✳
✶✻ ✴ ✶✼ x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
✶ ◗✉❡r② ❳♦Pr(k, 1) = z1✱ ✳ ✳ ✳ ✱ ❳♦Pr(k, τ) = zτ ✷ ❉❡✜♥❡ f(l) = El(1)
✸ ❆♣♣❧② ❚❛♥✐✬s ❛❧❣♦r✐t❤♠ t♦ ✜♥❞ l1, . . . , lr−1, m s✳t✳
✶✻ ✴ ✶✼ x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
✶ ◗✉❡r② ❳♦Pr(k, 1) = z1✱ ✳ ✳ ✳ ✱ ❳♦Pr(k, τ) = zτ ✷ ❉❡✜♥❡ f(l) = El(1) · · · El(τ)
✸ ❆♣♣❧② ❚❛♥✐✬s ❛❧❣♦r✐t❤♠ t♦ ✜♥❞ l1, . . . , lr−1, m s✳t✳
✶✻ ✴ ✶✼ x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
✶ ◗✉❡r② ❳♦Pr(k, 1) = z1✱ ✳ ✳ ✳ ✱ ❳♦Pr(k, τ) = zτ ✷ ❉❡✜♥❡ f(l) = El(1) · · · El(τ)
✸ ❆♣♣❧② ❚❛♥✐✬s ❛❧❣♦r✐t❤♠ t♦ ✜♥❞ l1, . . . , lr−1, m s✳t✳
✶✻ ✴ ✶✼ x XoPr(k, x)
Ek1 Ek2 Ekr−1 Ekr
· · ·
✶✼ ✴ ✶✼
✶✽ ✴ ✶✼
blockcipher random permutation
✶✾ ✴ ✶✼
blockcipher random permutation
✶✾ ✴ ✶✼
blockcipher random permutation
E (D) =
random function
F (D) =
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✷✶ ✴ ✶✼
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✷✶ ✴ ✶✼
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✷✶ ✴ ✶✼
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✷✶ ✴ ✶✼