❊♥❝r②♣t❡❞ ❉❛✈✐❡s✲▼❡②❡r ❛♥❞ ■ts ❉✉❛❧✿ ❚♦✇❛r❞s ❖♣t✐♠❛❧ ❙❡❝✉r✐t② ❯s✐♥❣ ▼✐rr♦r ❚❤❡♦r②
❇❛rt ▼❡♥♥✐♥❦✱ ❙❛♠✉❡❧ ◆❡✈❡s ❘❛❞❜♦✉❞ ❯♥✐✈❡rs✐t② ✭❚❤❡ ◆❡t❤❡r❧❛♥❞s✮✱ ❯♥✐✈❡rs✐t② ♦❢ ❈♦✐♠❜r❛ ✭P♦rt✉❣❛❧✮
❈❘❨P❚❖ ✷✵✶✼ ❆✉❣✉st ✷✹✱ ✷✵✶✼
✶ ✴ ✷✸
rt sr ts - - PowerPoint PPT Presentation
rt sr ts rs t rt s rrr r rt
✶ ✴ ✷✸
✷ ✴ ✷✸
✷ ✴ ✷✸
✷ ✴ ✷✸
✸ ✴ ✷✸
1· 0·
✸ ✴ ✷✸
✹ ✴ ✷✸
✹ ✴ ✷✸
✺ ✴ ✷✸
❊❛r❧✐❡r ♣r♦♣♦s❛❧ r❡♠♦✈❡❞ ❛❢t❡r ♦❜s❡r✈❛t✐♦♥ ❜② ◆❛♥❞✐
✺ ✴ ✷✸
❊❛r❧✐❡r ♣r♦♣♦s❛❧ r❡♠♦✈❡❞ ❛❢t❡r ♦❜s❡r✈❛t✐♦♥ ❜② ◆❛♥❞✐
✺ ✴ ✷✸
− − − − → ❊❛r❧✐❡r ♣r♦♣♦s❛❧ EWCDMD r❡♠♦✈❡❞ ❛❢t❡r ♦❜s❡r✈❛t✐♦♥ ❜② ◆❛♥❞✐
✺ ✴ ✷✸
− − − − → ❊❛r❧✐❡r ♣r♦♣♦s❛❧ EWCDMD r❡♠♦✈❡❞ ❛❢t❡r ♦❜s❡r✈❛t✐♦♥ ❜② ◆❛♥❞✐
✻ ✴ ✷✸
✻ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
✼ ✴ ✷✸
Pa1 =Pa2 Pb1 Pb3 Pa4 =Pa5 Pb5 Pb2 =Pa3 =Pb4
λ1 λ2 λ3 λ4 λ5
Pa6 Pb6
λ6
Pa7 Pb7
λ7
Pa8 Pa9 Pb8 =Pb9 =Pb10 =Pa11 Pa10 Pb11
λ8 λ9 λ10 λ11 ✽ ✴ ✷✸
✾ ✴ ✷✸
λ1 λ2
✾ ✴ ✷✸
λ1 λ2
✾ ✴ ✷✸
λ1 λ2
✾ ✴ ✷✸
λ1 λ2
✾ ✴ ✷✸
λ1 λ2
✶✵ ✴ ✷✸
λ1 λ2
✶✵ ✴ ✷✸
λ1 λ2
✶✵ ✴ ✷✸
λ1 λ2
✶✵ ✴ ✷✸
λ1 λ2
✶✵ ✴ ✷✸
λ1 λ2
✶✶ ✴ ✷✸
λ1 λ2 λ3
✶✶ ✴ ✷✸
λ1 λ2 λ3
✶✶ ✴ ✷✸
λ1 λ2 λ3
Pa1 = Pb5 Pb1 = Pa2 Pb2 = Pa3 Pb3 = Pa4 Pb4 = Pa5
λ1 λ2 λ3 λ4 λ5
Pa1 =Pa2 Pb1 Pa3 =Pa4 Pb4 = Pa5 Pb2 =Pb3
λ1 λ2 λ3 λ4
Pa8 Pb7 = Pb8
λ1 ⊕ λ2 ⊕ · · · ⊕ λ7
Pb5 = Pa6 Pb6 = Pb7
λ6 λ5 λ7 ✶✷ ✴ ✷✸
✶✸ ✴ ✷✸
1· 0·
✶✹ ✴ ✷✸
1· 0·
✶✹ ✴ ✷✸
1· 0·
✶✹ ✴ ✷✸
1· 0·
✶✹ ✴ ✷✸
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
✶✺ ✴ ✷✸
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
✶✺ ✴ ✷✸
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
2nq
✶✺ ✴ ✷✸
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
✶✻ ✴ ✷✸
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
✶✻ ✴ ✷✸
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
✶✻ ✴ ✷✸
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
1 2nq
✶✻ ✴ ✷✸
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
1 2nq
✶✻ ✴ ✷✸
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
1 2nq
XoP(q) ≤ q/2n
✶✻ ✴ ✷✸
✶✼ ✴ ✷✸
✶✼ ✴ ✷✸
✶✼ ✴ ✷✸
2 (yi) =: Pbi
✶✼ ✴ ✷✸
2 (yi) =: Pbi
✶✼ ✴ ✷✸
2 (yi) =: Pbi
✶✼ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
x1 x2 xξ1
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
xξ1+
1
xξ1+
2
xξ1+
ξ2
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
xq✕ξs+
1
xq✕ξs+
2
xq
✶✽ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
x1 x2 xξ1
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
xξ1+
1
xξ1+
2
xξ1+
ξ2
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
xq✕ξs+
1
xq✕ξs+
2
xq
✶✽ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
x1 x2 xξ1
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
xξ1+
1
xξ1+
2
xξ1+
ξ2
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
xq✕ξs+
1
xq✕ξs+
2
xq
✶✽ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
x1 x2 xξ1
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
xξ1+
1
xξ1+
2
xξ1+
ξ2
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
xq✕ξs+
1
xq✕ξs+
2
xq
2nq
✶✽ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
x1 x2 xξ1
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
xξ1+
1
xξ1+
2
xξ1+
ξ2
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
xq✕ξs+
1
xq✕ξs+
2
xq
2nq
EDM(q) ≤ q/2n +
ξ+1
✶✽ ✴ ✷✸
✶✾ ✴ ✷✸
✶✾ ✴ ✷✸
2 (ti) =: Pbi
✶✾ ✴ ✷✸
2 (ti) =: Pbi
✶✾ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
ν1 ⊕ h(m1) ν2 ⊕ h ( m2 ) νξ1 ⊕ h(mξ1)
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
νξ1+
1 ⊕ h(mξ1+ 1)
νξ1+
2 ⊕ h(mξ1+ 2)
ν
ξ
1
+ ξ
2
⊕ h ( m
ξ
1
+ ξ
2
)
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
ν
q✕ξ
s
+ 1
⊕ h ( m
q✕ξ
s
+ 1
) νq✕ξs+
2 ⊕ h(m q ✕ ξs + 2)
ν
q
⊕ h ( m
q
)
✷✵ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
ν1 ⊕ h(m1) ν2 ⊕ h ( m2 ) νξ1 ⊕ h(mξ1)
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
νξ1+
1 ⊕ h(mξ1+ 1)
νξ1+
2 ⊕ h(mξ1+ 2)
ν
ξ
1
+ ξ
2
⊕ h ( m
ξ
1
+ ξ
2
)
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
ν
q✕ξ
s
+ 1
⊕ h ( m
q✕ξ
s
+ 1
) νq✕ξs+
2 ⊕ h(m q ✕ ξs + 2)
ν
q
⊕ h ( m
q
)
✷✵ ✴ ✷✸
Pa1 Pa2 Paξ1 Pb1
ν1 ⊕ h(m1) ν2 ⊕ h ( m2 ) νξ1 ⊕ h(mξ1)
Paξ1+
1
Paξ1+
2
Paξ1+
ξ2
Pb2
νξ1+
1 ⊕ h(mξ1+ 1)
νξ1+
2 ⊕ h(mξ1+ 2)
ν
ξ
1
+ ξ
2
⊕ h ( m
ξ
1
+ ξ
2
)
· · · Paq✕ξs+
1
Paq✕ξs+
2
Paq Pbs
ν
q✕ξ
s
+ 1
⊕ h ( m
q✕ξ
s
+ 1
) νq✕ξs+
2 ⊕ h(m q ✕ ξs + 2)
ν
q
⊕ h ( m
q
)
EWCDM(q) ≤ q/2n +
2
ξ+1
✷✵ ✴ ✷✸
✷✶ ✴ ✷✸
✷✶ ✴ ✷✸
✷✶ ✴ ✷✸
EDMD(D) ≤ q/2n
✷✶ ✴ ✷✸
✷✷ ✴ ✷✸
✷✷ ✴ ✷✸
✷✷ ✴ ✷✸
✷✸ ✴ ✷✸
✷✸ ✴ ✷✸
✷✹ ✴ ✷✸
blockcipher random permutation
✷✺ ✴ ✷✸
blockcipher random permutation
✷✺ ✴ ✷✸
blockcipher random permutation
✷✺ ✴ ✷✸
blockcipher random permutation
E (D) =
random function
F (D) =
✷✼ ✴ ✷✸
CTR[E](σ) ≤ Advprp E (σ) +
✷✼ ✴ ✷✸
CTR[E](σ) ≤ Advprp E (σ) +
✷✼ ✴ ✷✸
✷✽ ✴ ✷✸
CTR[E](σ)
✷✽ ✴ ✷✸
✷✾ ✴ ✷✸
CTR[F](σ) ≤ Advprf F (σ)
✷✾ ✴ ✷✸
CTR[F](σ) ≤ Advprf F (σ)
✷✾ ✴ ✷✸
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](σ) ≤ Advprf XoP(σ)
✸✵ ✴ ✷✸
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](σ) ≤ Advprf XoP(σ)
E (2σ) + σ/2n
✸✵ ✴ ✷✸
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](σ) ≤ Advprf XoP(σ)
E (2σ) + σ/2n
✸✵ ✴ ✷✸
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✸✶ ✴ ✷✸
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✸✶ ✴ ✷✸
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✸✶ ✴ ✷✸
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✸✶ ✴ ✷✸
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
✸✷ ✴ ✷✸
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
✸✷ ✴ ✷✸
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
2nq
✸✷ ✴ ✷✸
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
2nq
CENC(q) ≤ q/2n + wq/2n+1
✸✷ ✴ ✷✸
blockcipher random function
✸✸ ✴ ✷✸
blockcipher random function
E (q) ≤ Advprp E (q) +
✸✸ ✴ ✷✸
✸✹ ✴ ✷✸