rt ttt rt - - PowerPoint PPT Presentation

r t t t t r t s
SMART_READER_LITE
LIVE PREVIEW

rt ttt rt - - PowerPoint PPT Presentation

rt ttt rt s rt rst trs


slide-1
SLIDE 1

❙❡❝✉r✐t② ♦❢ ❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥ ▼♦❞❡s

❇❛rt ▼❡♥♥✐♥❦ ❘❛❞❜♦✉❞ ❯♥✐✈❡rs✐t② ✭❚❤❡ ◆❡t❤❡r❧❛♥❞s✮

❈❖❙❚ ❚r❛✐♥✐♥❣ ❙❝❤♦♦❧ ♦♥ ❙②♠♠❡tr✐❝ ❈r②♣t♦❣r❛♣❤② ❛♥❞ ❇❧♦❝❦❝❤❛✐♥ ❋❡❜r✉❛r② ✷✷✱ ✷✵✶✽

✶ ✴ ✺✼

slide-2
SLIDE 2

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

← − − − − − − − − − − − − − − − − − − − − − − − − − − − − → ❇ ❊♥❝r②♣t✐♦♥ ◆♦ ♦✉ts✐❞❡r ❝❛♥ ❧❡❛r♥ ❛♥②t❤✐♥❣ ❛❜♦✉t ❞❛t❛ ❆✉t❤❡♥t✐❝❛t✐♦♥ ◆♦ ♦✉ts✐❞❡r ❝❛♥ ♠❛♥✐♣✉❧❛t❡ ❞❛t❛

✷ ✴ ✺✼

slide-3
SLIDE 3

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

← − − − − − − − − − − − − − − − − − − − − − − − − − − − − → ❇ − − − − − → ← − − − − − ❊♥❝r②♣t✐♦♥ ◆♦ ♦✉ts✐❞❡r ❝❛♥ ❧❡❛r♥ ❛♥②t❤✐♥❣ ❛❜♦✉t ❞❛t❛ ❆✉t❤❡♥t✐❝❛t✐♦♥ ◆♦ ♦✉ts✐❞❡r ❝❛♥ ♠❛♥✐♣✉❧❛t❡ ❞❛t❛

✷ ✴ ✺✼

slide-4
SLIDE 4

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

← − − − − − − − − − − − − − − − − − − − − − − − − − − − − → ❇ − − − − − → ← − − − − − ❊♥❝r②♣t✐♦♥

  • ◆♦ ♦✉ts✐❞❡r ❝❛♥ ❧❡❛r♥ ❛♥②t❤✐♥❣ ❛❜♦✉t ❞❛t❛

❆✉t❤❡♥t✐❝❛t✐♦♥ ◆♦ ♦✉ts✐❞❡r ❝❛♥ ♠❛♥✐♣✉❧❛t❡ ❞❛t❛

✷ ✴ ✺✼

slide-5
SLIDE 5

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

← − − − − − − − − − − − − − − − − − − − − − − − − − − − − → ❇ − − − − − → ← − − − − − ❊♥❝r②♣t✐♦♥

  • ◆♦ ♦✉ts✐❞❡r ❝❛♥ ❧❡❛r♥ ❛♥②t❤✐♥❣ ❛❜♦✉t ❞❛t❛

❆✉t❤❡♥t✐❝❛t✐♦♥

  • ◆♦ ♦✉ts✐❞❡r ❝❛♥ ♠❛♥✐♣✉❧❛t❡ ❞❛t❛

✷ ✴ ✺✼

slide-6
SLIDE 6

❈❆❊❙❆❘ ❈♦♠♣❡t✐t✐♦♥

✸ ✴ ✺✼

slide-7
SLIDE 7

❈❆❊❙❆❘ ❈♦♠♣❡t✐t✐♦♥ ❈♦♠♣❡t✐t✐♦♥ ❢♦r ❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥✿ ❙❡❝✉r✐t②✱ ❆♣♣❧✐❝❛❜✐❧✐t②✱ ❛♥❞ ❘♦❜✉st♥❡ss

  • ♦❛❧✿ ♣♦rt❢♦❧✐♦ ♦❢ ❛✉t❤❡♥t✐❝❛t❡❞ ❡♥❝r②♣t✐♦♥ s❝❤❡♠❡s

▼❛r ✶✺✱ ✷✵✶✹✿ ✺✼ ✜rst r♦✉♥❞ ❝❛♥❞✐❞❛t❡s ❏✉❧ ✼✱ ✷✵✶✺✿ ✷✾✳✺ s❡❝♦♥❞ r♦✉♥❞ ❝❛♥❞✐❞❛t❡s ❆✉❣ ✶✺✱ ✷✵✶✻✿ ✶✻ t❤✐r❞ r♦✉♥❞ ❝❛♥❞✐❞❛t❡s ❄❄✿ ❛♥♥♦✉♥❝❡♠❡♥t ♦❢ ✜♥❛❧✐sts ❄❄✿ ❛♥♥♦✉♥❝❡♠❡♥t ♦❢ ✜♥❛❧ ♣♦rt❢♦❧✐♦

✹ ✴ ✺✼

slide-8
SLIDE 8

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

A, M N C, T

AE

k

  • ❈✐♣❤❡rt❡①t C ❡♥❝r②♣t✐♦♥ ♦❢ ♠❡ss❛❣❡ M
  • ❚❛❣ T ❛✉t❤❡♥t✐❝❛t❡s ❛ss♦❝✐❛t❡❞ ❞❛t❛ A ❛♥❞ ♠❡ss❛❣❡ M

◆♦♥❝❡ r❛♥❞♦♠✐③❡s t❤❡ s❝❤❡♠❡

✺ ✴ ✺✼

slide-9
SLIDE 9

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

A, M N C, T

AE

k

  • ❈✐♣❤❡rt❡①t C ❡♥❝r②♣t✐♦♥ ♦❢ ♠❡ss❛❣❡ M
  • ❚❛❣ T ❛✉t❤❡♥t✐❝❛t❡s ❛ss♦❝✐❛t❡❞ ❞❛t❛ A ❛♥❞ ♠❡ss❛❣❡ M
  • ◆♦♥❝❡ N r❛♥❞♦♠✐③❡s t❤❡ s❝❤❡♠❡

✺ ✴ ✺✼

slide-10
SLIDE 10

❆✉t❤❡♥t✐❝❛t❡❞ ❉❡❝r②♣t✐♦♥

A, C, T N

  • M if T correct

⊥ otherwise

AD

k

  • ❆✉t❤❡♥t✐❝❛t❡❞ ❞❡❝r②♣t✐♦♥ ♥❡❡❞s t♦ s❛t✐s❢② t❤❛t
  • ▼❡ss❛❣❡ ❞✐s❝❧♦s❡❞ ✐❢ t❛❣ ✐s ❝♦rr❡❝t
  • ▼❡ss❛❣❡ ✐s ♥♦t ❧❡❛❦❡❞ ✐❢ t❛❣ ✐s ✐♥❝♦rr❡❝t

❈♦rr❡❝t♥❡ss✿

✻ ✴ ✺✼

slide-11
SLIDE 11

❆✉t❤❡♥t✐❝❛t❡❞ ❉❡❝r②♣t✐♦♥

A, C, T N

  • M if T correct

⊥ otherwise

AD

k

  • ❆✉t❤❡♥t✐❝❛t❡❞ ❞❡❝r②♣t✐♦♥ ♥❡❡❞s t♦ s❛t✐s❢② t❤❛t
  • ▼❡ss❛❣❡ ❞✐s❝❧♦s❡❞ ✐❢ t❛❣ ✐s ❝♦rr❡❝t
  • ▼❡ss❛❣❡ ✐s ♥♦t ❧❡❛❦❡❞ ✐❢ t❛❣ ✐s ✐♥❝♦rr❡❝t

❈♦rr❡❝t♥❡ss✿

✻ ✴ ✺✼

slide-12
SLIDE 12

❆✉t❤❡♥t✐❝❛t❡❞ ❉❡❝r②♣t✐♦♥

A, C, T N

  • M if T correct

⊥ otherwise

AD

k

  • ❆✉t❤❡♥t✐❝❛t❡❞ ❞❡❝r②♣t✐♦♥ ♥❡❡❞s t♦ s❛t✐s❢② t❤❛t
  • ▼❡ss❛❣❡ ❞✐s❝❧♦s❡❞ ✐❢ t❛❣ ✐s ❝♦rr❡❝t
  • ▼❡ss❛❣❡ ✐s ♥♦t ❧❡❛❦❡❞ ✐❢ t❛❣ ✐s ✐♥❝♦rr❡❝t
  • ❈♦rr❡❝t♥❡ss✿ ADk(N, A, AE k(N, A, M)) = M

✻ ✴ ✺✼

slide-13
SLIDE 13

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥ ❙❡❝✉r✐t②

IC

AE k, ADk $, ⊥

distinguisher D

AE scheme random cipher, ⊥ function

  • ❚✇♦ ♦r❛❝❧❡s✿ (AE k, ADk) ✭❢♦r s❡❝r❡t ❦❡② k✮ ❛♥❞ ($, ⊥)

❉✐st✐♥❣✉✐s❤❡r ❤❛s q✉❡r② ❛❝❝❡ss t♦ ♦♥❡ ♦❢ t❤❡s❡ ✉♥✐q✉❡ ♥♦♥❝❡ ❢♦r ❡❛❝❤ ❡♥❝r②♣t✐♦♥ q✉❡r② tr✐❡s t♦ ❞❡t❡r♠✐♥❡ ✇❤✐❝❤ ♦r❛❝❧❡ ✐t ❝♦♠♠✉♥✐❝❛t❡s ✇✐t❤

✼ ✴ ✺✼

slide-14
SLIDE 14

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥ ❙❡❝✉r✐t②

IC

AE k, ADk $, ⊥

distinguisher D

AE scheme random cipher, ⊥ function

  • ❚✇♦ ♦r❛❝❧❡s✿ (AE k, ADk) ✭❢♦r s❡❝r❡t ❦❡② k✮ ❛♥❞ ($, ⊥)
  • ❉✐st✐♥❣✉✐s❤❡r D ❤❛s q✉❡r② ❛❝❝❡ss t♦ ♦♥❡ ♦❢ t❤❡s❡

→ ✉♥✐q✉❡ ♥♦♥❝❡ ❢♦r ❡❛❝❤ ❡♥❝r②♣t✐♦♥ q✉❡r② tr✐❡s t♦ ❞❡t❡r♠✐♥❡ ✇❤✐❝❤ ♦r❛❝❧❡ ✐t ❝♦♠♠✉♥✐❝❛t❡s ✇✐t❤

✼ ✴ ✺✼

slide-15
SLIDE 15

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥ ❙❡❝✉r✐t②

IC

AE k, ADk $, ⊥

distinguisher D

AE scheme random cipher, ⊥ function

  • ❚✇♦ ♦r❛❝❧❡s✿ (AE k, ADk) ✭❢♦r s❡❝r❡t ❦❡② k✮ ❛♥❞ ($, ⊥)
  • ❉✐st✐♥❣✉✐s❤❡r D ❤❛s q✉❡r② ❛❝❝❡ss t♦ ♦♥❡ ♦❢ t❤❡s❡

→ ✉♥✐q✉❡ ♥♦♥❝❡ ❢♦r ❡❛❝❤ ❡♥❝r②♣t✐♦♥ q✉❡r②

  • D tr✐❡s t♦ ❞❡t❡r♠✐♥❡ ✇❤✐❝❤ ♦r❛❝❧❡ ✐t ❝♦♠♠✉♥✐❝❛t❡s ✇✐t❤

✼ ✴ ✺✼

slide-16
SLIDE 16

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥ ❙❡❝✉r✐t②

IC

AE k, ADk $, ⊥

distinguisher D

AE scheme random cipher, ⊥ function

  • ❚✇♦ ♦r❛❝❧❡s✿ (AE k, ADk) ✭❢♦r s❡❝r❡t ❦❡② k✮ ❛♥❞ ($, ⊥)
  • ❉✐st✐♥❣✉✐s❤❡r D ❤❛s q✉❡r② ❛❝❝❡ss t♦ ♦♥❡ ♦❢ t❤❡s❡

→ ✉♥✐q✉❡ ♥♦♥❝❡ ❢♦r ❡❛❝❤ ❡♥❝r②♣t✐♦♥ q✉❡r②

  • D tr✐❡s t♦ ❞❡t❡r♠✐♥❡ ✇❤✐❝❤ ♦r❛❝❧❡ ✐t ❝♦♠♠✉♥✐❝❛t❡s ✇✐t❤

Advae

AE(D) =

  • Pr
  • DAE k,ADk = 1
  • − Pr
  • D$,⊥ = 1
  • ✼ ✴ ✺✼
slide-17
SLIDE 17

✶✵✵✪ ❙❡❝✉r✐t② ✐s ■♠♣r❛❝t✐❝❛❧

✽ ✴ ✺✼

slide-18
SLIDE 18

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣ ◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✾ ✴ ✺✼

slide-19
SLIDE 19

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣ ◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✶✵ ✴ ✺✼

slide-20
SLIDE 20
  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥
  • ●❡♥❡r✐❝ ❝♦♥str✉❝t✐♦♥s ❢♦r ❆❊✿
  • ❊♥❝ ✰ ▼❆❈ ❂ ❆❊

❇❡❧❧❛r❡ ❛♥❞ ◆❛♠♣r❡♠♣r❡ ✭✷✵✵✵✮✿ ✸ ❜❛s✐❝ ❛♣♣r♦❛❝❤❡s ❊✫▼ ▼t❊ ❊t▼ ❯s❡❞ ✐♥ ❙❙❍

  • ❡♥❡r✐❝❛❧❧② ✐♥s❡❝✉r❡

▼❆❈

❯s❡❞ ✐♥ ❚▲❙ ▼✐❧❞❧② ✐♥s❡❝✉r❡ P❛❞❞✐♥❣ ♦r❛❝❧❡ ❛tt❛❝❦ ❯s❡❞ ✐♥ ■P❙❡❝ ▼♦st s❡❝✉r❡ ✈❛r✐❛♥t ❈✐♣❤❡rt❡①t ✐♥t❡❣r✐t②

✶✶ ✴ ✺✼

slide-21
SLIDE 21
  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥
  • ●❡♥❡r✐❝ ❝♦♥str✉❝t✐♦♥s ❢♦r ❆❊✿
  • ❊♥❝ ✰ ▼❆❈ ❂ ❆❊
  • ❇❡❧❧❛r❡ ❛♥❞ ◆❛♠♣r❡♠♣r❡ ✭✷✵✵✵✮✿ ✸ ❜❛s✐❝ ❛♣♣r♦❛❝❤❡s

❊✫▼ ▼t❊ ❊t▼

Enck Enck Enck MACl MACl MACl m m m c c c t t t

  • ❯s❡❞ ✐♥ ❙❙❍
  • ❡♥❡r✐❝❛❧❧② ✐♥s❡❝✉r❡

▼❆❈

  • ❯s❡❞ ✐♥ ❚▲❙

▼✐❧❞❧② ✐♥s❡❝✉r❡ P❛❞❞✐♥❣ ♦r❛❝❧❡ ❛tt❛❝❦

  • ❯s❡❞ ✐♥ ■P❙❡❝

▼♦st s❡❝✉r❡ ✈❛r✐❛♥t ❈✐♣❤❡rt❡①t ✐♥t❡❣r✐t②

✶✶ ✴ ✺✼

slide-22
SLIDE 22
  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥
  • ●❡♥❡r✐❝ ❝♦♥str✉❝t✐♦♥s ❢♦r ❆❊✿
  • ❊♥❝ ✰ ▼❆❈ ❂ ❆❊
  • ❇❡❧❧❛r❡ ❛♥❞ ◆❛♠♣r❡♠♣r❡ ✭✷✵✵✵✮✿ ✸ ❜❛s✐❝ ❛♣♣r♦❛❝❤❡s

❊✫▼ ▼t❊ ❊t▼

Enck Enck Enck MACl MACl MACl m m m c c c t t t

  • ❯s❡❞ ✐♥ ❙❙❍
  • ●❡♥❡r✐❝❛❧❧② ✐♥s❡❝✉r❡
  • ▼❆❈L(m) = mt
  • ❯s❡❞ ✐♥ ❚▲❙

▼✐❧❞❧② ✐♥s❡❝✉r❡ P❛❞❞✐♥❣ ♦r❛❝❧❡ ❛tt❛❝❦

  • ❯s❡❞ ✐♥ ■P❙❡❝

▼♦st s❡❝✉r❡ ✈❛r✐❛♥t ❈✐♣❤❡rt❡①t ✐♥t❡❣r✐t②

✶✶ ✴ ✺✼

slide-23
SLIDE 23
  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥
  • ●❡♥❡r✐❝ ❝♦♥str✉❝t✐♦♥s ❢♦r ❆❊✿
  • ❊♥❝ ✰ ▼❆❈ ❂ ❆❊
  • ❇❡❧❧❛r❡ ❛♥❞ ◆❛♠♣r❡♠♣r❡ ✭✷✵✵✵✮✿ ✸ ❜❛s✐❝ ❛♣♣r♦❛❝❤❡s

❊✫▼ ▼t❊ ❊t▼

Enck Enck Enck MACl MACl MACl m m m c c c t t t

  • ❯s❡❞ ✐♥ ❙❙❍
  • ●❡♥❡r✐❝❛❧❧② ✐♥s❡❝✉r❡
  • ▼❆❈L(m) = mt
  • ❯s❡❞ ✐♥ ❚▲❙
  • ▼✐❧❞❧② ✐♥s❡❝✉r❡
  • P❛❞❞✐♥❣ ♦r❛❝❧❡

❛tt❛❝❦

  • ❯s❡❞ ✐♥ ■P❙❡❝

▼♦st s❡❝✉r❡ ✈❛r✐❛♥t ❈✐♣❤❡rt❡①t ✐♥t❡❣r✐t②

✶✶ ✴ ✺✼

slide-24
SLIDE 24
  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥
  • ●❡♥❡r✐❝ ❝♦♥str✉❝t✐♦♥s ❢♦r ❆❊✿
  • ❊♥❝ ✰ ▼❆❈ ❂ ❆❊
  • ❇❡❧❧❛r❡ ❛♥❞ ◆❛♠♣r❡♠♣r❡ ✭✷✵✵✵✮✿ ✸ ❜❛s✐❝ ❛♣♣r♦❛❝❤❡s

❊✫▼ ▼t❊ ❊t▼

Enck Enck Enck MACl MACl MACl m m m c c c t t t

  • ❯s❡❞ ✐♥ ❙❙❍
  • ●❡♥❡r✐❝❛❧❧② ✐♥s❡❝✉r❡
  • ▼❆❈L(m) = mt
  • ❯s❡❞ ✐♥ ❚▲❙
  • ▼✐❧❞❧② ✐♥s❡❝✉r❡
  • P❛❞❞✐♥❣ ♦r❛❝❧❡

❛tt❛❝❦

  • ❯s❡❞ ✐♥ ■P❙❡❝
  • ▼♦st s❡❝✉r❡ ✈❛r✐❛♥t
  • ❈✐♣❤❡rt❡①t ✐♥t❡❣r✐t②

✶✶ ✴ ✺✼

slide-25
SLIDE 25
  • ❈▼ ❢♦r 96✲❜✐t ♥♦♥❝❡ N

N1 N2 N3 N(m + 1)

M1 M2 Mm

C1 C2 Cm

A

T EK EK EK EK GHASHL ENC MAC

  • ▼❝●r❡✇ ❛♥❞ ❱✐❡❣❛ ✭✷✵✵✹✮
  • ❊t▼ ❞❡s✐❣♥
  • ❲✐❞❡❧② ✉s❡❞ ✭❚▲❙✦✮
  • P❛t❡♥t✲❢r❡❡

P❛r❛❧❧❡❧✐③❛❜❧❡ ❊✈❛❧✉❛t❡s ♦♥❧② ✭♥♦ ✮ Pr♦✈❛❜❧② s❡❝✉r❡ ✭✐❢ ✐s P❘P✮ ❱❡r② ❡✣❝✐❡♥t ✐♥ ❍❲ ❘❡❛s♦♥❛❜❧② ❡✣❝✐❡♥t ✐♥ ❙❲

❲❤❛t ❤❛♣♣❡♥s ✐❢ ♥♦♥❝❡ ✐s r❡✲✉s❡❞❄

✶✷ ✴ ✺✼

slide-26
SLIDE 26
  • ❈▼ ❢♦r 96✲❜✐t ♥♦♥❝❡ N

N1 N2 N3 N(m + 1)

M1 M2 Mm

C1 C2 Cm

A

T EK EK EK EK GHASHL ENC MAC

  • ▼❝●r❡✇ ❛♥❞ ❱✐❡❣❛ ✭✷✵✵✹✮
  • ❊t▼ ❞❡s✐❣♥
  • ❲✐❞❡❧② ✉s❡❞ ✭❚▲❙✦✮
  • P❛t❡♥t✲❢r❡❡
  • P❛r❛❧❧❡❧✐③❛❜❧❡
  • ❊✈❛❧✉❛t❡s E ♦♥❧② ✭♥♦ E−1✮
  • Pr♦✈❛❜❧② s❡❝✉r❡

✭✐❢ E ✐s P❘P✮

  • ❱❡r② ❡✣❝✐❡♥t ✐♥ ❍❲
  • ❘❡❛s♦♥❛❜❧② ❡✣❝✐❡♥t ✐♥ ❙❲

❲❤❛t ❤❛♣♣❡♥s ✐❢ ♥♦♥❝❡ ✐s r❡✲✉s❡❞❄

✶✷ ✴ ✺✼

slide-27
SLIDE 27
  • ❈▼ ❢♦r 96✲❜✐t ♥♦♥❝❡ N

N1 N2 N3 N(m + 1)

M1 M2 Mm

C1 C2 Cm

A

T EK EK EK EK GHASHL ENC MAC

  • ▼❝●r❡✇ ❛♥❞ ❱✐❡❣❛ ✭✷✵✵✹✮
  • ❊t▼ ❞❡s✐❣♥
  • ❲✐❞❡❧② ✉s❡❞ ✭❚▲❙✦✮
  • P❛t❡♥t✲❢r❡❡
  • P❛r❛❧❧❡❧✐③❛❜❧❡
  • ❊✈❛❧✉❛t❡s E ♦♥❧② ✭♥♦ E−1✮
  • Pr♦✈❛❜❧② s❡❝✉r❡

✭✐❢ E ✐s P❘P✮

  • ❱❡r② ❡✣❝✐❡♥t ✐♥ ❍❲
  • ❘❡❛s♦♥❛❜❧② ❡✣❝✐❡♥t ✐♥ ❙❲

❲❤❛t ❤❛♣♣❡♥s ✐❢ ♥♦♥❝❡ ✐s r❡✲✉s❡❞❄

✶✷ ✴ ✺✼

slide-28
SLIDE 28
  • ❈▼✲❙■❱

N

N

(K, L) T +0 T +1 T +(m−1) M1 M2 Mm

C1 C2 Cm A

T EK EK EK EK GHASHL KeyGenEk KEY ENC MAC

  • ●✉❡r♦♥ ❛♥❞ ▲✐♥❞❡❧❧ ✭✷✵✶✺✮
  • ▼t❊ ❞❡s✐❣♥
  • ❖♥❣♦✐♥❣ st❛♥❞❛r❞✐③❛t✐♦♥

✭■❊❚❋ ❘❋❈✮

  • P❛t❡♥t✲❢r❡❡

■♥❤❡r✐ts ●❈▼ ❢❡❛t✉r❡s ❙❡❝✉r❡ ❛❣❛✐♥st ♥♦♥❝❡✲r❡✉s❡ Pr♦♦❢✿ ■✇❛t❛ ❛♥❞ ❙❡✉r✐♥ ✭✷✵✶✼✮

✶✸ ✴ ✺✼

slide-29
SLIDE 29
  • ❈▼✲❙■❱

N

N

(K, L) T +0 T +1 T +(m−1) M1 M2 Mm

C1 C2 Cm A

T EK EK EK EK GHASHL KeyGenEk KEY ENC MAC

  • ●✉❡r♦♥ ❛♥❞ ▲✐♥❞❡❧❧ ✭✷✵✶✺✮
  • ▼t❊ ❞❡s✐❣♥
  • ❖♥❣♦✐♥❣ st❛♥❞❛r❞✐③❛t✐♦♥

✭■❊❚❋ ❘❋❈✮

  • P❛t❡♥t✲❢r❡❡
  • ■♥❤❡r✐ts ●❈▼ ❢❡❛t✉r❡s
  • ❙❡❝✉r❡ ❛❣❛✐♥st ♥♦♥❝❡✲r❡✉s❡
  • Pr♦♦❢✿ ■✇❛t❛ ❛♥❞ ❙❡✉r✐♥

✭✷✵✶✼✮

✶✸ ✴ ✺✼

slide-30
SLIDE 30

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣ ◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✶✹ ✴ ✺✼

slide-31
SLIDE 31

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs

m c

E

k ❚✇❡❛❦✿ ✢❡①✐❜✐❧✐t② t♦ t❤❡ ❝✐♣❤❡r ❊❛❝❤ t✇❡❛❦ ❣✐✈❡s ❞✐✛❡r❡♥t ♣❡r♠✉t❛t✐♦♥

✶✺ ✴ ✺✼

slide-32
SLIDE 32

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs

m t c k

  • E
  • ❚✇❡❛❦✿ ✢❡①✐❜✐❧✐t② t♦ t❤❡ ❝✐♣❤❡r
  • ❊❛❝❤ t✇❡❛❦ ❣✐✈❡s ❞✐✛❡r❡♥t ♣❡r♠✉t❛t✐♦♥

✶✺ ✴ ✺✼

slide-33
SLIDE 33

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡r ❙❡❝✉r✐t②

IC

  • Ek
  • π

distinguisher D

tweakable blockcipher random tweakable permutation

Ek s❤♦✉❧❞ ❧♦♦❦ ❧✐❦❡ r❛♥❞♦♠ ♣❡r♠✉t❛t✐♦♥ ❢♦r ❡✈❡r② t

  • ❉✐✛❡r❡♥t t✇❡❛❦s −

→ ♣s❡✉❞♦✲✐♥❞❡♣❡♥❞❡♥t ♣❡r♠✉t❛t✐♦♥s tr✐❡s t♦ ❞❡t❡r♠✐♥❡ ✇❤✐❝❤ ♦r❛❝❧❡ ✐t ❝♦♠♠✉♥✐❝❛t❡s ✇✐t❤

✶✻ ✴ ✺✼

slide-34
SLIDE 34

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡r ❙❡❝✉r✐t②

IC

  • Ek
  • π

distinguisher D

tweakable blockcipher random tweakable permutation

Ek s❤♦✉❧❞ ❧♦♦❦ ❧✐❦❡ r❛♥❞♦♠ ♣❡r♠✉t❛t✐♦♥ ❢♦r ❡✈❡r② t

  • ❉✐✛❡r❡♥t t✇❡❛❦s −

→ ♣s❡✉❞♦✲✐♥❞❡♣❡♥❞❡♥t ♣❡r♠✉t❛t✐♦♥s

  • D tr✐❡s t♦ ❞❡t❡r♠✐♥❡ ✇❤✐❝❤ ♦r❛❝❧❡ ✐t ❝♦♠♠✉♥✐❝❛t❡s ✇✐t❤

Advstprp

  • E

(D) =

  • Pr
  • D
  • Ek,

E−1

k

= 1

  • − Pr
  • D

π, π−1 = 1

  • ✶✻ ✴ ✺✼
slide-35
SLIDE 35

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡r ❉❡s✐❣♥s ✐♥ ❈❆❊❙❆❘

  • E

t

E

  • E

P

  • E

❉❡❞✐❝❛t❡❞ ❇❧♦❝❦❝✐♣❤❡r✲❇❛s❡❞ P❡r♠✉t❛t✐♦♥✲❇❛s❡❞ ❑■❆❙❯✱ ❈❇❆✱ ❈❖❇❘❆✱ ✐❋❡❡❞✱ Prøst✱ ❏♦❧t✐❦✱ ▼❛r❜❧❡✱ ❖▼❉✱ P❖❊❚✱ ▼✐♥❛❧♣❤❡r ❙❈❘❊❆▼✱ ❙❍❊▲▲✱ ❆❊❩✱ ❈❖P❆✴ ❉❡♦①②s ❊▲♠❉✱ ❖❈❇✱ ❖❚❘

✶✼ ✴ ✺✼

✜rst r♦✉♥❞✱ s❡❝♦♥❞ r♦✉♥❞✱ t❤✐r❞ r♦✉♥❞

slide-36
SLIDE 36

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡r ❉❡s✐❣♥s ✐♥ ❈❆❊❙❆❘

  • E

t

E

  • E

P

  • E

❉❡❞✐❝❛t❡❞ ❇❧♦❝❦❝✐♣❤❡r✲❇❛s❡❞ P❡r♠✉t❛t✐♦♥✲❇❛s❡❞ ❑■❆❙❯✱ ❈❇❆✱ ❈❖❇❘❆✱ ✐❋❡❡❞✱ Prøst✱ ❏♦❧t✐❦✱ ▼❛r❜❧❡✱ ❖▼❉✱ P❖❊❚✱ ▼✐♥❛❧♣❤❡r ❙❈❘❊❆▼✱ ❙❍❊▲▲✱ ❆❊❩✱ ❈❖P❆✴ ❉❡♦①②s ❊▲♠❉✱ ❖❈❇✱ ❖❚❘

✶✼ ✴ ✺✼

✜rst r♦✉♥❞✱ s❡❝♦♥❞ r♦✉♥❞✱ t❤✐r❞ r♦✉♥❞

slide-37
SLIDE 37

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✶✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E

N,tA1 k

˜ E

N,tA2 k

˜ E

N,tAa k

˜ E

N,tM⊕ k

˜ E

N,tM1 k

˜ E

N,tM2 k

˜ E

N,tMd k

  • ●❡♥❡r❛❧✐③❡❞ ❖❈❇ ❜② ❘♦❣❛✇❛② ❡t ❛❧✳ ❬❘❇❇❑✵✶✱❘♦❣✵✹✱❑❘✶✶❪

■♥t❡r♥❛❧❧② ❜❛s❡❞ ♦♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

❚✇❡❛❦ ✐s ✉♥✐q✉❡ ❢♦r ❡✈❡r② ❡✈❛❧✉❛t✐♦♥ ❉✐✛❡r❡♥t ❜❧♦❝❦s ❛❧✇❛②s tr❛♥s❢♦r♠❡❞ ✉♥❞❡r ❞✐✛❡r❡♥t t✇❡❛❦

❚r✐❛♥❣❧❡ ✐♥❡q✉❛❧✐t②✿

✶✽ ✴ ✺✼

slide-38
SLIDE 38

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✶✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E

N,tA1 k

˜ E

N,tA2 k

˜ E

N,tAa k

˜ E

N,tM⊕ k

˜ E

N,tM1 k

˜ E

N,tM2 k

˜ E

N,tMd k

  • ●❡♥❡r❛❧✐③❡❞ ❖❈❇ ❜② ❘♦❣❛✇❛② ❡t ❛❧✳ ❬❘❇❇❑✵✶✱❘♦❣✵✹✱❑❘✶✶❪
  • ■♥t❡r♥❛❧❧② ❜❛s❡❞ ♦♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

E

  • ❚✇❡❛❦ (N, tweak) ✐s ✉♥✐q✉❡ ❢♦r ❡✈❡r② ❡✈❛❧✉❛t✐♦♥
  • ❉✐✛❡r❡♥t ❜❧♦❝❦s ❛❧✇❛②s tr❛♥s❢♦r♠❡❞ ✉♥❞❡r ❞✐✛❡r❡♥t t✇❡❛❦

❚r✐❛♥❣❧❡ ✐♥❡q✉❛❧✐t②✿

✶✽ ✴ ✺✼

slide-39
SLIDE 39

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✶✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E

N,tA1 k

˜ E

N,tA2 k

˜ E

N,tAa k

˜ E

N,tM⊕ k

˜ E

N,tM1 k

˜ E

N,tM2 k

˜ E

N,tMd k

  • ●❡♥❡r❛❧✐③❡❞ ❖❈❇ ❜② ❘♦❣❛✇❛② ❡t ❛❧✳ ❬❘❇❇❑✵✶✱❘♦❣✵✹✱❑❘✶✶❪
  • ■♥t❡r♥❛❧❧② ❜❛s❡❞ ♦♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

E

  • ❚✇❡❛❦ (N, tweak) ✐s ✉♥✐q✉❡ ❢♦r ❡✈❡r② ❡✈❛❧✉❛t✐♦♥
  • ❉✐✛❡r❡♥t ❜❧♦❝❦s ❛❧✇❛②s tr❛♥s❢♦r♠❡❞ ✉♥❞❡r ❞✐✛❡r❡♥t t✇❡❛❦

❚r✐❛♥❣❧❡ ✐♥❡q✉❛❧✐t②✿ Advae

AE[ Ek](σ)

✶✽ ✴ ✺✼

slide-40
SLIDE 40

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✶✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ●❡♥❡r❛❧✐③❡❞ ❖❈❇ ❜② ❘♦❣❛✇❛② ❡t ❛❧✳ ❬❘❇❇❑✵✶✱❘♦❣✵✹✱❑❘✶✶❪
  • ■♥t❡r♥❛❧❧② ❜❛s❡❞ ♦♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

E

  • ❚✇❡❛❦ (N, tweak) ✐s ✉♥✐q✉❡ ❢♦r ❡✈❡r② ❡✈❛❧✉❛t✐♦♥
  • ❉✐✛❡r❡♥t ❜❧♦❝❦s ❛❧✇❛②s tr❛♥s❢♦r♠❡❞ ✉♥❞❡r ❞✐✛❡r❡♥t t✇❡❛❦
  • ❚r✐❛♥❣❧❡ ✐♥❡q✉❛❧✐t②✿

Advae

AE[ Ek](σ) ≤ Advae AE[ π](σ)

✶✽ ✴ ✺✼

slide-41
SLIDE 41

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✶✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ●❡♥❡r❛❧✐③❡❞ ❖❈❇ ❜② ❘♦❣❛✇❛② ❡t ❛❧✳ ❬❘❇❇❑✵✶✱❘♦❣✵✹✱❑❘✶✶❪
  • ■♥t❡r♥❛❧❧② ❜❛s❡❞ ♦♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

E

  • ❚✇❡❛❦ (N, tweak) ✐s ✉♥✐q✉❡ ❢♦r ❡✈❡r② ❡✈❛❧✉❛t✐♦♥
  • ❉✐✛❡r❡♥t ❜❧♦❝❦s ❛❧✇❛②s tr❛♥s❢♦r♠❡❞ ✉♥❞❡r ❞✐✛❡r❡♥t t✇❡❛❦
  • ❚r✐❛♥❣❧❡ ✐♥❡q✉❛❧✐t②✿

Advae

AE[ Ek](σ) ≤ Advae AE[ π](σ) + Advstprp

  • E

(σ)

✶✽ ✴ ✺✼

slide-42
SLIDE 42

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

◆♦♥❝❡ ✉♥✐q✉❡♥❡ss t✇❡❛❦ ✉♥✐q✉❡♥❡ss ❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥

❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-43
SLIDE 43

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ◆♦♥❝❡ ✉♥✐q✉❡♥❡ss ⇒ t✇❡❛❦ ✉♥✐q✉❡♥❡ss

❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥

❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-44
SLIDE 44

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ◆♦♥❝❡ ✉♥✐q✉❡♥❡ss ⇒ t✇❡❛❦ ✉♥✐q✉❡♥❡ss
  • ❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ AE[

π] = $ ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥

❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-45
SLIDE 45

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ◆♦♥❝❡ ✉♥✐q✉❡♥❡ss ⇒ t✇❡❛❦ ✉♥✐q✉❡♥❡ss
  • ❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ AE[

π] = $

  • ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥

❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-46
SLIDE 46

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ◆♦♥❝❡ ✉♥✐q✉❡♥❡ss ⇒ t✇❡❛❦ ✉♥✐q✉❡♥❡ss
  • ❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ AE[

π] = $

  • ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥
  • ❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st 1/(2n − 1)

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-47
SLIDE 47

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ◆♦♥❝❡ ✉♥✐q✉❡♥❡ss ⇒ t✇❡❛❦ ✉♥✐q✉❡♥❡ss
  • ❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ AE[

π] = $

  • ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥
  • ❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st 1/(2n − 1)

Advae

AE[ π](σ) ≤ 1/(2n − 1)

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-48
SLIDE 48

❊①❛♠♣❧❡ ❯s❡ ✐♥ ❖❈❇① ✭✷✴✷✮

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ π

N,tA1

˜ π

N,tA2

˜ π

N,tAa

˜ π

N,tM⊕

˜ π

N,tM1

˜ π

N,tM2

˜ π

N,tMd

  • ◆♦♥❝❡ ✉♥✐q✉❡♥❡ss ⇒ t✇❡❛❦ ✉♥✐q✉❡♥❡ss
  • ❊♥❝r②♣t✐♦♥ ❝❛❧❧s ❜❡❤❛✈❡ ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥s✿ AE[

π] = $

  • ❆✉t❤❡♥t✐❝❛t✐♦♥ ❜❡❤❛✈❡s ❧✐❦❡ r❛♥❞♦♠ ❢✉♥❝t✐♦♥
  • ❚❛❣ ❢♦r❣❡❞ ✇✐t❤ ♣r♦❜❛❜✐❧✐t② ❛t ♠♦st 1/(2n − 1)

Advae

AE[ π](σ) ≤ 1/(2n − 1)

✶✾ ✴ ✺✼

❚♦ ❞♦✿ ❞❡s✐❣♥ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡r

slide-49
SLIDE 49

❉❡❞✐❝❛t❡❞ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs

  • ❍❛st② P✉❞❞✐♥❣ ❈✐♣❤❡r ❬❙❝❤✾✽❪
  • ❆❊❙ s✉❜♠✐ss✐♦♥✱ ✏✜rst t✇❡❛❦❛❜❧❡ ❝✐♣❤❡r✑
  • ▼❡r❝② ❬❈r♦✵✶❪
  • ❉✐s❦ ❡♥❝r②♣t✐♦♥
  • ❚❤r❡❡✜s❤ ❬❋▲❙✰✵✼❪
  • ❙❍❆✲✸ s✉❜♠✐ss✐♦♥ ❙❦❡✐♥
  • ❚❲❊❆❑❊❨ ❢r❛♠❡✇♦r❦ ❬❏◆P✶✹❪
  • ❋♦✉r ❈❆❊❙❆❘ s✉❜♠✐ss✐♦♥s
  • ❙❑■◆◆❨ ✫ ▼❆◆❚■❙

✷✵ ✴ ✺✼

slide-50
SLIDE 50

❚❲❊❆❑❊❨ ❋r❛♠❡✇♦r❦

  • ❚❲❊❆❑❊❨ ❜② ❏❡❛♥ ❡t ❛❧✳ ❬❏◆P✶✹❪✿

(k, t) m c

· · · · · · · · · · · ·

f f f g g g g h h h

  • f✿ r♦✉♥❞ ❢✉♥❝t✐♦♥
  • g✿ s✉❜❦❡② ❝♦♠♣✉t❛t✐♦♥
  • h✿ tr❛♥s❢♦r♠❛t✐♦♥ ♦❢ (k, t)

❙❡❝✉r✐t② ♠❡❛s✉r❡❞ t❤r♦✉❣❤ ❝r②♣t❛♥❛❧②s✐s ❖✉r ❢♦❝✉s✿ ♠♦❞✉❧❛r ❞❡s✐❣♥

✷✶ ✴ ✺✼

slide-51
SLIDE 51

❚❲❊❆❑❊❨ ❋r❛♠❡✇♦r❦

  • ❚❲❊❆❑❊❨ ❜② ❏❡❛♥ ❡t ❛❧✳ ❬❏◆P✶✹❪✿

(k, t) m c

· · · · · · · · · · · ·

f f f g g g g h h h

  • f✿ r♦✉♥❞ ❢✉♥❝t✐♦♥
  • g✿ s✉❜❦❡② ❝♦♠♣✉t❛t✐♦♥
  • h✿ tr❛♥s❢♦r♠❛t✐♦♥ ♦❢ (k, t)
  • ❙❡❝✉r✐t② ♠❡❛s✉r❡❞ t❤r♦✉❣❤ ❝r②♣t❛♥❛❧②s✐s
  • ❖✉r ❢♦❝✉s✿ ♠♦❞✉❧❛r ❞❡s✐❣♥

✷✶ ✴ ✺✼

slide-52
SLIDE 52

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐♦♥
  • ❙t❛t❡ ♦❢ t❤❡ ❆rt
  • ■♠♣r♦✈❡❞ ❊✣❝✐❡♥❝②
  • ■♠♣r♦✈❡❞ ❙❡❝✉r✐t②

◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✷✷ ✴ ✺✼

slide-53
SLIDE 53

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t ?

  • ❈♦♥s✐❞❡r ❛ ❜❧♦❝❦❝✐♣❤❡r E ✇✐t❤ κ✲❜✐t ❦❡② ❛♥❞ n✲❜✐t st❛t❡

❍♦✇ t♦ ♠✐♥❣❧❡ t❤❡ t✇❡❛❦ ✐♥t♦ t❤❡ ❡✈❛❧✉❛t✐♦♥❄ ❜❧❡♥❞ ✐t ✇✐t❤ t❤❡ ❦❡② ❜❧❡♥❞ ✐t ✇✐t❤ t❤❡ st❛t❡

✷✸ ✴ ✺✼

slide-54
SLIDE 54

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t ?

  • ❈♦♥s✐❞❡r ❛ ❜❧♦❝❦❝✐♣❤❡r E ✇✐t❤ κ✲❜✐t ❦❡② ❛♥❞ n✲❜✐t st❛t❡

❍♦✇ t♦ ♠✐♥❣❧❡ t❤❡ t✇❡❛❦ ✐♥t♦ t❤❡ ❡✈❛❧✉❛t✐♦♥❄

← − − − ← − − −

❜❧❡♥❞ ✐t ✇✐t❤ t❤❡ ❦❡② ❜❧❡♥❞ ✐t ✇✐t❤ t❤❡ st❛t❡

✷✸ ✴ ✺✼

slide-55
SLIDE 55

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t

  • ❇❧❡♥❞✐♥❣ t✇❡❛❦ ❛♥❞ ❦❡② ✇♦r❦s✳ ✳ ✳
  • ✳ ✳ ✳ ❜✉t✿ ❝❛r❡❢✉❧ ✇✐t❤ r❡❧❛t❡❞✲❦❡② ❛tt❛❝❦s✦

❋♦r ✲♠✐①✐♥❣✱ ❦❡② ❝❛♥ ❜❡ r❡❝♦✈❡r❡❞ ✐♥ ❡✈❛❧✉❛t✐♦♥s ❙❝❤❡♠❡ ✐s ✐♥s❡❝✉r❡ ✐❢ ✐s ❊✈❡♥✲▼❛♥s♦✉r ❚❲❊❆❑❊❨ ❜❧❡♥❞✐♥❣ ❬❏◆P✶✹❪ ✐s ♠♦r❡ ❛❞✈❛♥❝❡❞

✷✹ ✴ ✺✼

slide-56
SLIDE 56

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t

  • ❇❧❡♥❞✐♥❣ t✇❡❛❦ ❛♥❞ ❦❡② ✇♦r❦s✳ ✳ ✳
  • ✳ ✳ ✳ ❜✉t✿ ❝❛r❡❢✉❧ ✇✐t❤ r❡❧❛t❡❞✲❦❡② ❛tt❛❝❦s✦
  • ❋♦r ⊕✲♠✐①✐♥❣✱ ❦❡② ❝❛♥ ❜❡ r❡❝♦✈❡r❡❞ ✐♥ 2κ/2 ❡✈❛❧✉❛t✐♦♥s
  • ❙❝❤❡♠❡ ✐s ✐♥s❡❝✉r❡ ✐❢ E ✐s ❊✈❡♥✲▼❛♥s♦✉r

❚❲❊❆❑❊❨ ❜❧❡♥❞✐♥❣ ❬❏◆P✶✹❪ ✐s ♠♦r❡ ❛❞✈❛♥❝❡❞

✷✹ ✴ ✺✼

slide-57
SLIDE 57

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t

  • ❇❧❡♥❞✐♥❣ t✇❡❛❦ ❛♥❞ ❦❡② ✇♦r❦s✳ ✳ ✳
  • ✳ ✳ ✳ ❜✉t✿ ❝❛r❡❢✉❧ ✇✐t❤ r❡❧❛t❡❞✲❦❡② ❛tt❛❝❦s✦
  • ❋♦r ⊕✲♠✐①✐♥❣✱ ❦❡② ❝❛♥ ❜❡ r❡❝♦✈❡r❡❞ ✐♥ 2κ/2 ❡✈❛❧✉❛t✐♦♥s
  • ❙❝❤❡♠❡ ✐s ✐♥s❡❝✉r❡ ✐❢ E ✐s ❊✈❡♥✲▼❛♥s♦✉r
  • ❚❲❊❆❑❊❨ ❜❧❡♥❞✐♥❣ ❬❏◆P✶✹❪ ✐s ♠♦r❡ ❛❞✈❛♥❝❡❞

✷✹ ✴ ✺✼

slide-58
SLIDE 58

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t

  • ❙✐♠♣❧❡ ❜❧❡♥❞✐♥❣ ♦❢ t✇❡❛❦ ❛♥❞ st❛t❡ ❞♦❡s ♥♦t ✇♦r❦

❙♦♠❡ s❡❝r❡❝② r❡q✉✐r❡❞✿ ❙t✐❧❧ ❞♦❡s ♥♦t ✇♦r❦ ✐❢ ❛❞✈❡rs❛r② ❤❛s ❛❝❝❡ss t♦

❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②

✷✺ ✴ ✺✼

slide-59
SLIDE 59

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k t

  • ❙✐♠♣❧❡ ❜❧❡♥❞✐♥❣ ♦❢ t✇❡❛❦ ❛♥❞ st❛t❡ ❞♦❡s ♥♦t ✇♦r❦

Ek(t, m) = Ek(t ⊕ C, m ⊕ C)

❙♦♠❡ s❡❝r❡❝② r❡q✉✐r❡❞✿ ❙t✐❧❧ ❞♦❡s ♥♦t ✇♦r❦ ✐❢ ❛❞✈❡rs❛r② ❤❛s ❛❝❝❡ss t♦

❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②

✷✺ ✴ ✺✼

slide-60
SLIDE 60

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k h ⊗ t

  • ❙✐♠♣❧❡ ❜❧❡♥❞✐♥❣ ♦❢ t✇❡❛❦ ❛♥❞ st❛t❡ ❞♦❡s ♥♦t ✇♦r❦

Ek(t, m) = Ek(t ⊕ C, m ⊕ C)

  • ❙♦♠❡ s❡❝r❡❝② r❡q✉✐r❡❞✿ h

❙t✐❧❧ ❞♦❡s ♥♦t ✇♦r❦ ✐❢ ❛❞✈❡rs❛r② ❤❛s ❛❝❝❡ss t♦

❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②

✷✺ ✴ ✺✼

slide-61
SLIDE 61

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k h ⊗ t

  • ❙✐♠♣❧❡ ❜❧❡♥❞✐♥❣ ♦❢ t✇❡❛❦ ❛♥❞ st❛t❡ ❞♦❡s ♥♦t ✇♦r❦

Ek(t, m) = Ek(t ⊕ C, m ⊕ C)

  • ❙♦♠❡ s❡❝r❡❝② r❡q✉✐r❡❞✿ h
  • ❙t✐❧❧ ❞♦❡s ♥♦t ✇♦r❦ ✐❢ ❛❞✈❡rs❛r② ❤❛s ❛❝❝❡ss t♦

E−1

k

❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②

✷✺ ✴ ✺✼

slide-62
SLIDE 62

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k h ⊗ t

  • ❙✐♠♣❧❡ ❜❧❡♥❞✐♥❣ ♦❢ t✇❡❛❦ ❛♥❞ st❛t❡ ❞♦❡s ♥♦t ✇♦r❦

Ek(t, m) = Ek(t ⊕ C, m ⊕ C)

  • ❙♦♠❡ s❡❝r❡❝② r❡q✉✐r❡❞✿ h
  • ❙t✐❧❧ ❞♦❡s ♥♦t ✇♦r❦ ✐❢ ❛❞✈❡rs❛r② ❤❛s ❛❝❝❡ss t♦

E−1

k

E−1

k (t, c) ⊕

E−1

k (t ⊕ C, c) = h ⊗ C

❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②

✷✺ ✴ ✺✼

slide-63
SLIDE 63

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k h ⊗ t h ⊗ t

  • ❙✐♠♣❧❡ ❜❧❡♥❞✐♥❣ ♦❢ t✇❡❛❦ ❛♥❞ st❛t❡ ❞♦❡s ♥♦t ✇♦r❦

Ek(t, m) = Ek(t ⊕ C, m ⊕ C)

  • ❙♦♠❡ s❡❝r❡❝② r❡q✉✐r❡❞✿ h
  • ❙t✐❧❧ ❞♦❡s ♥♦t ✇♦r❦ ✐❢ ❛❞✈❡rs❛r② ❤❛s ❛❝❝❡ss t♦

E−1

k

E−1

k (t, c) ⊕

E−1

k (t ⊕ C, c) = h ⊗ C

  • ❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②

✷✺ ✴ ✺✼

slide-64
SLIDE 64

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k h ⊗ t h ⊗ t

  • ❚✇♦✲s✐❞❡❞ s❡❝r❡t ♠❛s❦✐♥❣ s❡❡♠s t♦ ✇♦r❦
  • ❈❛♥ ✇❡ ❣❡♥❡r❛❧✐③❡❄
  • ❡♥❡r❛❧✐③✐♥❣ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥

❱❛r✐❛t✐♦♥ ✐♥ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥s ❘❡❧❡❛s✐♥❣ s❡❝r❡❝② ✐♥ ❄ ❯s✉❛❧❧② ♥♦ ♣r♦❜❧❡♠

✷✻ ✴ ✺✼

▼❛❥♦r✐t② ♦❢ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡rs ❢♦❧❧♦✇ ♠❛s❦✲ ✲♠❛s❦ ♣r✐♥❝✐♣❧❡

slide-65
SLIDE 65

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k f(t) f(t)

  • ❚✇♦✲s✐❞❡❞ s❡❝r❡t ♠❛s❦✐♥❣ s❡❡♠s t♦ ✇♦r❦
  • ❈❛♥ ✇❡ ❣❡♥❡r❛❧✐③❡❄
  • ●❡♥❡r❛❧✐③✐♥❣ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥ f

❱❛r✐❛t✐♦♥ ✐♥ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥s ❘❡❧❡❛s✐♥❣ s❡❝r❡❝② ✐♥ ❄ ❯s✉❛❧❧② ♥♦ ♣r♦❜❧❡♠

✷✻ ✴ ✺✼

▼❛❥♦r✐t② ♦❢ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡rs ❢♦❧❧♦✇ ♠❛s❦✲ ✲♠❛s❦ ♣r✐♥❝✐♣❧❡

slide-66
SLIDE 66

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

E

k f1(t) f2(t)

  • ❚✇♦✲s✐❞❡❞ s❡❝r❡t ♠❛s❦✐♥❣ s❡❡♠s t♦ ✇♦r❦
  • ❈❛♥ ✇❡ ❣❡♥❡r❛❧✐③❡❄
  • ●❡♥❡r❛❧✐③✐♥❣ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥ f
  • ❱❛r✐❛t✐♦♥ ✐♥ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥s f1, f2

❘❡❧❡❛s✐♥❣ s❡❝r❡❝② ✐♥ ❄ ❯s✉❛❧❧② ♥♦ ♣r♦❜❧❡♠

✷✻ ✴ ✺✼

▼❛❥♦r✐t② ♦❢ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡rs ❢♦❧❧♦✇ ♠❛s❦✲ ✲♠❛s❦ ♣r✐♥❝✐♣❧❡

slide-67
SLIDE 67

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

P

f1(t) f2(t)

  • ❚✇♦✲s✐❞❡❞ s❡❝r❡t ♠❛s❦✐♥❣ s❡❡♠s t♦ ✇♦r❦
  • ❈❛♥ ✇❡ ❣❡♥❡r❛❧✐③❡❄
  • ●❡♥❡r❛❧✐③✐♥❣ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥ f
  • ❱❛r✐❛t✐♦♥ ✐♥ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥s f1, f2
  • ❘❡❧❡❛s✐♥❣ s❡❝r❡❝② ✐♥ E❄ ❯s✉❛❧❧② ♥♦ ♣r♦❜❧❡♠

✷✻ ✴ ✺✼

▼❛❥♦r✐t② ♦❢ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡rs ❢♦❧❧♦✇ ♠❛s❦✲ ✲♠❛s❦ ♣r✐♥❝✐♣❧❡

slide-68
SLIDE 68

■♥t✉✐t✐♦♥✿ ❉❡s✐❣♥

m c

P

f1(t) f2(t)

  • ❚✇♦✲s✐❞❡❞ s❡❝r❡t ♠❛s❦✐♥❣ s❡❡♠s t♦ ✇♦r❦
  • ❈❛♥ ✇❡ ❣❡♥❡r❛❧✐③❡❄
  • ●❡♥❡r❛❧✐③✐♥❣ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥ f
  • ❱❛r✐❛t✐♦♥ ✐♥ ♠❛s❦✐♥❣❄ ❉❡♣❡♥❞s ♦♥ ❢✉♥❝t✐♦♥s f1, f2
  • ❘❡❧❡❛s✐♥❣ s❡❝r❡❝② ✐♥ E❄ ❯s✉❛❧❧② ♥♦ ♣r♦❜❧❡♠

✷✻ ✴ ✺✼

▼❛❥♦r✐t② ♦❢ t✇❡❛❦❛❜❧❡ ❜❧♦❝❦❝✐♣❤❡rs ❢♦❧❧♦✇ ♠❛s❦✲Ek/P✲♠❛s❦ ♣r✐♥❝✐♣❧❡

slide-69
SLIDE 69

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

Ek s❤♦✉❧❞ ✏❧♦♦❦ ❧✐❦❡✑ r❛♥❞♦♠ ♣❡r♠✉t❛t✐♦♥ ❢♦r ❡✈❡r② t

  • ❈♦♥s✐❞❡r ❛❞✈❡rs❛r② D t❤❛t ♠❛❦❡s q ❡✈❛❧✉❛t✐♦♥s ♦❢

Ek ❙t❡♣ ✶✿

❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s ♥❡❡❞ ❛t ♠♦st❄

❙t❡♣ ✶✿

❇♦✐❧s ❞♦✇♥ t♦ ✜♥❞✐♥❣ ❣❡♥❡r✐❝ ❛tt❛❝❦s

❙t❡♣ ✷✿

❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s ♥❡❡❞ ❛t ❧❡❛st❄

❙t❡♣ ✷✿

❇♦✐❧s ❞♦✇♥ t♦ ♣r♦✈❛❜❧❡ s❡❝✉r✐t②

✷✼ ✴ ✺✼

slide-70
SLIDE 70

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

Ek s❤♦✉❧❞ ✏❧♦♦❦ ❧✐❦❡✑ r❛♥❞♦♠ ♣❡r♠✉t❛t✐♦♥ ❢♦r ❡✈❡r② t

  • ❈♦♥s✐❞❡r ❛❞✈❡rs❛r② D t❤❛t ♠❛❦❡s q ❡✈❛❧✉❛t✐♦♥s ♦❢

Ek

  • ❙t❡♣ ✶✿ • ❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s D ♥❡❡❞ ❛t ♠♦st❄

❙t❡♣ ✶✿ • ❇♦✐❧s ❞♦✇♥ t♦ ✜♥❞✐♥❣ ❣❡♥❡r✐❝ ❛tt❛❝❦s ❙t❡♣ ✷✿

❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s ♥❡❡❞ ❛t ❧❡❛st❄

❙t❡♣ ✷✿

❇♦✐❧s ❞♦✇♥ t♦ ♣r♦✈❛❜❧❡ s❡❝✉r✐t②

✷✼ ✴ ✺✼

slide-71
SLIDE 71

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

Ek s❤♦✉❧❞ ✏❧♦♦❦ ❧✐❦❡✑ r❛♥❞♦♠ ♣❡r♠✉t❛t✐♦♥ ❢♦r ❡✈❡r② t

  • ❈♦♥s✐❞❡r ❛❞✈❡rs❛r② D t❤❛t ♠❛❦❡s q ❡✈❛❧✉❛t✐♦♥s ♦❢

Ek

  • ❙t❡♣ ✶✿ • ❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s D ♥❡❡❞ ❛t ♠♦st❄

❙t❡♣ ✶✿ • ❇♦✐❧s ❞♦✇♥ t♦ ✜♥❞✐♥❣ ❣❡♥❡r✐❝ ❛tt❛❝❦s

  • ❙t❡♣ ✷✿ • ❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s D ♥❡❡❞ ❛t ❧❡❛st❄

❙t❡♣ ✷✿ • ❇♦✐❧s ❞♦✇♥ t♦ ♣r♦✈❛❜❧❡ s❡❝✉r✐t②

✷✼ ✴ ✺✼

slide-72
SLIDE 72

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t) ❋♦r ❛♥② t✇♦ q✉❡r✐❡s ✱ ✿ ❯♥❧✐❦❡❧② t♦ ❤❛♣♣❡♥ ❢♦r r❛♥❞♦♠ ❢❛♠✐❧② ♦❢ ♣❡r♠✉t❛t✐♦♥s ■♠♣❧✐❝❛t✐♦♥ st✐❧❧ ❤♦❧❞s ✇✐t❤ ❞✐✛❡r❡♥❝❡ ①♦r❡❞ t♦

❙❝❤❡♠❡ ❝❛♥ ❜❡ ❜r♦❦❡♥ ✐♥ ❡✈❛❧✉❛t✐♦♥s

✷✽ ✴ ✺✼

slide-73
SLIDE 73

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❋♦r ❛♥② t✇♦ q✉❡r✐❡s (t, m, c)✱ (t′, m′, c′)✿

m ⊕ f1(t) = m′ ⊕ f1(t′) = ⇒ c ⊕ f2(t) = c′ ⊕ f2(t′) ❯♥❧✐❦❡❧② t♦ ❤❛♣♣❡♥ ❢♦r r❛♥❞♦♠ ❢❛♠✐❧② ♦❢ ♣❡r♠✉t❛t✐♦♥s ■♠♣❧✐❝❛t✐♦♥ st✐❧❧ ❤♦❧❞s ✇✐t❤ ❞✐✛❡r❡♥❝❡ ①♦r❡❞ t♦

❙❝❤❡♠❡ ❝❛♥ ❜❡ ❜r♦❦❡♥ ✐♥ ❡✈❛❧✉❛t✐♦♥s

✷✽ ✴ ✺✼

slide-74
SLIDE 74

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❋♦r ❛♥② t✇♦ q✉❡r✐❡s (t, m, c)✱ (t′, m′, c′)✿

m ⊕ f1(t) = m′ ⊕ f1(t′) = ⇒ c ⊕ f2(t) = c′ ⊕ f2(t′)

  • ❯♥❧✐❦❡❧② t♦ ❤❛♣♣❡♥ ❢♦r r❛♥❞♦♠ ❢❛♠✐❧② ♦❢ ♣❡r♠✉t❛t✐♦♥s

■♠♣❧✐❝❛t✐♦♥ st✐❧❧ ❤♦❧❞s ✇✐t❤ ❞✐✛❡r❡♥❝❡ ①♦r❡❞ t♦

❙❝❤❡♠❡ ❝❛♥ ❜❡ ❜r♦❦❡♥ ✐♥ ❡✈❛❧✉❛t✐♦♥s

✷✽ ✴ ✺✼

slide-75
SLIDE 75

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❋♦r ❛♥② t✇♦ q✉❡r✐❡s (t, m, c)✱ (t′, m′, c′)✿

m ⊕ f1(t) = m′ ⊕ f1(t′) = ⇒ c ⊕ f2(t) = c′ ⊕ f2(t′)

  • ❯♥❧✐❦❡❧② t♦ ❤❛♣♣❡♥ ❢♦r r❛♥❞♦♠ ❢❛♠✐❧② ♦❢ ♣❡r♠✉t❛t✐♦♥s
  • ■♠♣❧✐❝❛t✐♦♥ st✐❧❧ ❤♦❧❞s ✇✐t❤ ❞✐✛❡r❡♥❝❡ C ①♦r❡❞ t♦ m, m′

❙❝❤❡♠❡ ❝❛♥ ❜❡ ❜r♦❦❡♥ ✐♥ ❡✈❛❧✉❛t✐♦♥s

✷✽ ✴ ✺✼

slide-76
SLIDE 76

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❋♦r ❛♥② t✇♦ q✉❡r✐❡s (t, m, c)✱ (t′, m′, c′)✿

m ⊕ f1(t) = m′ ⊕ f1(t′) = ⇒ c ⊕ f2(t) = c′ ⊕ f2(t′)

  • ❯♥❧✐❦❡❧② t♦ ❤❛♣♣❡♥ ❢♦r r❛♥❞♦♠ ❢❛♠✐❧② ♦❢ ♣❡r♠✉t❛t✐♦♥s
  • ■♠♣❧✐❝❛t✐♦♥ st✐❧❧ ❤♦❧❞s ✇✐t❤ ❞✐✛❡r❡♥❝❡ C ①♦r❡❞ t♦ m, m′

❙❝❤❡♠❡ ❝❛♥ ❜❡ ❜r♦❦❡♥ ✐♥ ≈ 2n/2 ❡✈❛❧✉❛t✐♦♥s

✷✽ ✴ ✺✼

slide-77
SLIDE 77

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❚❤❡ ❢✉♥ st❛rts ❤❡r❡✦
  • ▼♦r❡ t❡❝❤♥✐❝❛❧ ❛♥❞ ♦❢t❡♥ ♠♦r❡ ✐♥✈♦❧✈❡❞

❚②♣✐❝❛❧ ❛♣♣r♦❛❝❤✿

❈♦♥s✐❞❡r ❛♥② tr❛♥s❝r✐♣t ❛♥ ❛❞✈❡rs❛r② ♠❛② s❡❡ ▼♦st ✬s s❤♦✉❧❞ ❜❡ ❡q✉❛❧❧② ❧✐❦❡❧② ✐♥ ❜♦t❤ ✇♦r❧❞s ❖❞❞ ♦♥❡s s❤♦✉❧❞ ❤❛♣♣❡♥ ✇✐t❤ ✈❡r② s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②

❆❧❧ ❝♦♥str✉❝t✐♦♥s ✐♥ t❤✐s ♣r❡s❡♥t❛t✐♦♥✿ s❡❝✉r❡ ✉♣ t♦ ❡✈❛❧✉❛t✐♦♥s

✷✾ ✴ ✺✼

slide-78
SLIDE 78

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❚❤❡ ❢✉♥ st❛rts ❤❡r❡✦
  • ▼♦r❡ t❡❝❤♥✐❝❛❧ ❛♥❞ ♦❢t❡♥ ♠♦r❡ ✐♥✈♦❧✈❡❞
  • ❚②♣✐❝❛❧ ❛♣♣r♦❛❝❤✿
  • ❈♦♥s✐❞❡r ❛♥② tr❛♥s❝r✐♣t τ ❛♥ ❛❞✈❡rs❛r② ♠❛② s❡❡
  • ▼♦st τ✬s s❤♦✉❧❞ ❜❡ ❡q✉❛❧❧② ❧✐❦❡❧② ✐♥ ❜♦t❤ ✇♦r❧❞s
  • ❖❞❞ ♦♥❡s s❤♦✉❧❞ ❤❛♣♣❡♥ ✇✐t❤ ✈❡r② s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②

❆❧❧ ❝♦♥str✉❝t✐♦♥s ✐♥ t❤✐s ♣r❡s❡♥t❛t✐♦♥✿ s❡❝✉r❡ ✉♣ t♦ ❡✈❛❧✉❛t✐♦♥s

✷✾ ✴ ✺✼

slide-79
SLIDE 79

■♥t✉✐t✐♦♥✿ ❆♥❛❧②s✐s

m c

Ek/P

f1(t) f2(t)

  • ❚❤❡ ❢✉♥ st❛rts ❤❡r❡✦
  • ▼♦r❡ t❡❝❤♥✐❝❛❧ ❛♥❞ ♦❢t❡♥ ♠♦r❡ ✐♥✈♦❧✈❡❞
  • ❚②♣✐❝❛❧ ❛♣♣r♦❛❝❤✿
  • ❈♦♥s✐❞❡r ❛♥② tr❛♥s❝r✐♣t τ ❛♥ ❛❞✈❡rs❛r② ♠❛② s❡❡
  • ▼♦st τ✬s s❤♦✉❧❞ ❜❡ ❡q✉❛❧❧② ❧✐❦❡❧② ✐♥ ❜♦t❤ ✇♦r❧❞s
  • ❖❞❞ ♦♥❡s s❤♦✉❧❞ ❤❛♣♣❡♥ ✇✐t❤ ✈❡r② s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②

❆❧❧ ❝♦♥str✉❝t✐♦♥s ✐♥ t❤✐s ♣r❡s❡♥t❛t✐♦♥✿ s❡❝✉r❡ ✉♣ t♦ ≈ 2n/2 ❡✈❛❧✉❛t✐♦♥s

✷✾ ✴ ✺✼

slide-80
SLIDE 80

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐♦♥
  • ❙t❛t❡ ♦❢ t❤❡ ❆rt
  • ■♠♣r♦✈❡❞ ❊✣❝✐❡♥❝②
  • ■♠♣r♦✈❡❞ ❙❡❝✉r✐t②

◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✸✵ ✴ ✺✼

slide-81
SLIDE 81

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣

❇❧♦❝❦❝✐♣❤❡r✲❇❛s❡❞✳

m c tweak-based mask

Ek

t②♣✐❝❛❧❧② ✶✷✽ ❜✐ts

♣P❡r♠✉t❛t✐♦♥✲❇❛s❡❞✳♣

m c tweak-based mask

P

♠✉❝❤ ❧❛r❣❡r✿ ✷✺✻✲✶✻✵✵ ❜✐ts

✸✶ ✴ ✺✼

slide-82
SLIDE 82

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣

❇❧♦❝❦❝✐♣❤❡r✲❇❛s❡❞✳

m c tweak-based mask

Ek

t②♣✐❝❛❧❧② ✶✷✽ ❜✐ts

♣P❡r♠✉t❛t✐♦♥✲❇❛s❡❞✳♣

m c tweak-based mask

P

♠✉❝❤ ❧❛r❣❡r✿ ✷✺✻✲✶✻✵✵ ❜✐ts

✸✶ ✴ ✺✼

slide-83
SLIDE 83

❖r✐❣✐♥❛❧ ❈♦♥str✉❝t✐♦♥s

  • LRW1 ❛♥❞ LRW2 ❜② ▲✐s❦♦✈ ❡t ❛❧✳ ❬▲❘❲✵✷❪✿

m c t

Ek Ek

m c h(t)

Ek

  • h ✐s ❳❖❘✲✉♥✐✈❡rs❛❧ ❤❛s❤
  • ❊✳❣✳✱ h(t) = h ⊗ t ❢♦r n✲❜✐t ✏❦❡②✑ h

✸✷ ✴ ✺✼

slide-84
SLIDE 84

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✭❳❊❳✮

  • XEX ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪✿

m c 2α3β7γ · Ek(N)

Ek

  • (α, β, γ, N) ✐s t✇❡❛❦ ✭s✐♠♣❧✐✜❡❞✮

❯s❡❞ ✐♥ ❖❈❇✷ ❛♥❞ ✶✹ ❈❆❊❙❆❘ ❝❛♥❞✐❞❛t❡s P❡r♠✉t❛t✐♦♥✲❜❛s❡❞ ✈❛r✐❛♥ts ✐♥ ▼✐♥❛❧♣❤❡r ❛♥❞ Prøst ✭❣❡♥❡r❛❧✐③❡❞ ❜② ❈♦❣❧✐❛t✐ ❡t ❛❧✳ ❬❈▲❙✶✺❪✮

✸✸ ✴ ✺✼

slide-85
SLIDE 85

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✭❳❊❳✮

  • XEX ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪✿

m c 2α3β7γ · Ek(N)

Ek

  • (α, β, γ, N) ✐s t✇❡❛❦ ✭s✐♠♣❧✐✜❡❞✮
  • ❯s❡❞ ✐♥ ❖❈❇✷ ❛♥❞ ±✶✹ ❈❆❊❙❆❘ ❝❛♥❞✐❞❛t❡s

P❡r♠✉t❛t✐♦♥✲❜❛s❡❞ ✈❛r✐❛♥ts ✐♥ ▼✐♥❛❧♣❤❡r ❛♥❞ Prøst ✭❣❡♥❡r❛❧✐③❡❞ ❜② ❈♦❣❧✐❛t✐ ❡t ❛❧✳ ❬❈▲❙✶✺❪✮

✸✸ ✴ ✺✼

slide-86
SLIDE 86

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✭❳❊❳✮

  • XEX ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪✿

m c 2α3β7γ · Ek(N)

Ek

m c 2α3β7γ · (kN ⊕ P(kN))

P

  • (α, β, γ, N) ✐s t✇❡❛❦ ✭s✐♠♣❧✐✜❡❞✮
  • ❯s❡❞ ✐♥ ❖❈❇✷ ❛♥❞ ±✶✹ ❈❆❊❙❆❘ ❝❛♥❞✐❞❛t❡s
  • P❡r♠✉t❛t✐♦♥✲❜❛s❡❞ ✈❛r✐❛♥ts ✐♥ ▼✐♥❛❧♣❤❡r ❛♥❞ Prøst

✭❣❡♥❡r❛❧✐③❡❞ ❜② ❈♦❣❧✐❛t✐ ❡t ❛❧✳ ❬❈▲❙✶✺❪✮

✸✸ ✴ ✺✼

slide-87
SLIDE 87

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E

N,tA1 k

˜ E

N,tA2 k

˜ E

N,tAa k

˜ E

N,tM⊕ k

˜ E

N,tM1 k

˜ E

N,tM2 k

˜ E

N,tMd k

❯♣❞❛t❡ ♦❢ ♠❛s❦✿

❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘

❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥ ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-88
SLIDE 88

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

❯♣❞❛t❡ ♦❢ ♠❛s❦✿

❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘

❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥ ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-89
SLIDE 89

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

❯♣❞❛t❡ ♦❢ ♠❛s❦✿

❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘

❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥ ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-90
SLIDE 90

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

❯♣❞❛t❡ ♦❢ ♠❛s❦✿

❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘

❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥ ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-91
SLIDE 91

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

❯♣❞❛t❡ ♦❢ ♠❛s❦✿

❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘

❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥ ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-92
SLIDE 92

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

❯♣❞❛t❡ ♦❢ ♠❛s❦✿

❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘

❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥ ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-93
SLIDE 93

P♦✇❡r✐♥❣✲❯♣ ▼❛s❦✐♥❣ ✐♥ ❖❈❇✷

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

  • ❯♣❞❛t❡ ♦❢ ♠❛s❦✿
  • ❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
  • ❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥
  • ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✹ ✴ ✺✼

L = Ek(N)

slide-94
SLIDE 94

■♥t❡r♠❡③③♦✿ ❲❤② ❙t❛rt ❛t 2 · Ek(N)❄

A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T

2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL

Ek Ek Ek Ek Ek Ek Ek

  • ❯♣❞❛t❡ ♦❢ ♠❛s❦✿
  • ❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
  • ❱❛r✐❛❜❧❡ t✐♠❡ ❝♦♠♣✉t❛t✐♦♥
  • ❊①♣❡♥s✐✈❡ ♦♥ ❝❡rt❛✐♥ ♣❧❛t❢♦r♠s

✸✺ ✴ ✺✼

L = Ek(N)

slide-95
SLIDE 95

■♥t❡r♠❡③③♦✿ ❲❤② ❙t❛rt ❛t 2 · Ek(N)❄

  • ❙✉♣♣♦s❡ ✇❡ ✇♦✉❧❞ ♠❛s❦ ✇✐t❤ Ek(N)✿

m c Ek(N)

Ek

❉✐st✐♥❣✉✐s❤❡r ❝❛♥ ♠❛❦❡ ✐♥✈❡rs❡ q✉❡r✐❡s P✉tt✐♥❣ ❣✐✈❡s ❉✐st✐♥❣✉✐s❤❡r ❦♥♦✇s s♦ ❧❡❛r♥s ✏s✉❜❦❡②✑

✸✻ ✴ ✺✼

slide-96
SLIDE 96

■♥t❡r♠❡③③♦✿ ❲❤② ❙t❛rt ❛t 2 · Ek(N)❄

  • ❙✉♣♣♦s❡ ✇❡ ✇♦✉❧❞ ♠❛s❦ ✇✐t❤ Ek(N)✿

m c Ek(N)

E−1

k

  • ❉✐st✐♥❣✉✐s❤❡r ❝❛♥ ♠❛❦❡ ✐♥✈❡rs❡ q✉❡r✐❡s

P✉tt✐♥❣ ❣✐✈❡s ❉✐st✐♥❣✉✐s❤❡r ❦♥♦✇s s♦ ❧❡❛r♥s ✏s✉❜❦❡②✑

✸✻ ✴ ✺✼

slide-97
SLIDE 97

■♥t❡r♠❡③③♦✿ ❲❤② ❙t❛rt ❛t 2 · Ek(N)❄

  • ❙✉♣♣♦s❡ ✇❡ ✇♦✉❧❞ ♠❛s❦ ✇✐t❤ Ek(N)✿

Ek(N)

E−1

k N ⊕ Ek(N)

  • ❉✐st✐♥❣✉✐s❤❡r ❝❛♥ ♠❛❦❡ ✐♥✈❡rs❡ q✉❡r✐❡s
  • P✉tt✐♥❣ c = 0 ❣✐✈❡s m = N ⊕ Ek(N)

❉✐st✐♥❣✉✐s❤❡r ❦♥♦✇s s♦ ❧❡❛r♥s ✏s✉❜❦❡②✑

✸✻ ✴ ✺✼

slide-98
SLIDE 98

■♥t❡r♠❡③③♦✿ ❲❤② ❙t❛rt ❛t 2 · Ek(N)❄

  • ❙✉♣♣♦s❡ ✇❡ ✇♦✉❧❞ ♠❛s❦ ✇✐t❤ Ek(N)✿

Ek(N)

E−1

k N ⊕ Ek(N)

  • ❉✐st✐♥❣✉✐s❤❡r ❝❛♥ ♠❛❦❡ ✐♥✈❡rs❡ q✉❡r✐❡s
  • P✉tt✐♥❣ c = 0 ❣✐✈❡s m = N ⊕ Ek(N)
  • ❉✐st✐♥❣✉✐s❤❡r ❦♥♦✇s N s♦ ❧❡❛r♥s ✏s✉❜❦❡②✑ Ek(N)

✸✻ ✴ ✺✼

slide-99
SLIDE 99
  • r❛② ❈♦❞❡ ▼❛s❦✐♥❣
  • ❖❈❇✶ ❛♥❞ ❖❈❇✸ ✉s❡ ●r❛② ❈♦❞❡s✿

m c

  • α ⊕ (α ≫ 1)
  • · Ek(N)

Ek

  • (α, N) ✐s t✇❡❛❦
  • ❯♣❞❛t✐♥❣✿ G(α) = G(α − 1) ⊕ 2ntz(α)

❙✐♥❣❧❡ ❳❖❘ ▲♦❣❛r✐t❤♠✐❝ ❛♠♦✉♥t ♦❢ ✜❡❧❞ ❞♦✉❜❧✐♥❣s ✭♣r❡❝♦♠♣✉t❡❞✮

▼♦r❡ ❡✣❝✐❡♥t t❤❛♥ ♣♦✇❡r✐♥❣✲✉♣ ❬❑❘✶✶❪

✸✼ ✴ ✺✼

slide-100
SLIDE 100
  • r❛② ❈♦❞❡ ▼❛s❦✐♥❣
  • ❖❈❇✶ ❛♥❞ ❖❈❇✸ ✉s❡ ●r❛② ❈♦❞❡s✿

m c

  • α ⊕ (α ≫ 1)
  • · Ek(N)

Ek

  • (α, N) ✐s t✇❡❛❦
  • ❯♣❞❛t✐♥❣✿ G(α) = G(α − 1) ⊕ 2ntz(α)
  • ❙✐♥❣❧❡ ❳❖❘
  • ▲♦❣❛r✐t❤♠✐❝ ❛♠♦✉♥t ♦❢ ✜❡❧❞ ❞♦✉❜❧✐♥❣s ✭♣r❡❝♦♠♣✉t❡❞✮
  • ▼♦r❡ ❡✣❝✐❡♥t t❤❛♥ ♣♦✇❡r✐♥❣✲✉♣ ❬❑❘✶✶❪

✸✼ ✴ ✺✼

slide-101
SLIDE 101

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐♦♥
  • ❙t❛t❡ ♦❢ t❤❡ ❆rt
  • ■♠♣r♦✈❡❞ ❊✣❝✐❡♥❝②
  • ■♠♣r♦✈❡❞ ❙❡❝✉r✐t②

◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✸✽ ✴ ✺✼

slide-102
SLIDE 102

▼❛s❦❡❞ ❊✈❡♥✲▼❛♥s♦✉r ✭MEM✮

  • MEM ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪✿

m c ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 ◦ P(Nk)

P

  • ϕi ❛r❡ ✜①❡❞ ▲❋❙❘s✱ (α, β, γ, N) ✐s t✇❡❛❦ ✭s✐♠♣❧✐✜❡❞✮

❈♦♠❜✐♥❡s ❛❞✈❛♥t❛❣❡s ♦❢✿

P♦✇❡r✐♥❣✲✉♣ ♠❛s❦✐♥❣ ❲♦r❞✲❜❛s❡❞ ▲❋❙❘s

❙✐♠♣❧❡r✱ ❝♦♥st❛♥t✲t✐♠❡ ✭❜② ❞❡❢❛✉❧t✮✱ ♠♦r❡ ❡✣❝✐❡♥t

✸✾ ✴ ✺✼

slide-103
SLIDE 103

▼❛s❦❡❞ ❊✈❡♥✲▼❛♥s♦✉r ✭MEM✮

  • MEM ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪✿

m c ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 ◦ P(Nk)

P

  • ϕi ❛r❡ ✜①❡❞ ▲❋❙❘s✱ (α, β, γ, N) ✐s t✇❡❛❦ ✭s✐♠♣❧✐✜❡❞✮
  • ❈♦♠❜✐♥❡s ❛❞✈❛♥t❛❣❡s ♦❢✿
  • P♦✇❡r✐♥❣✲✉♣ ♠❛s❦✐♥❣
  • ❲♦r❞✲❜❛s❡❞ ▲❋❙❘s

❙✐♠♣❧❡r✱ ❝♦♥st❛♥t✲t✐♠❡ ✭❜② ❞❡❢❛✉❧t✮✱ ♠♦r❡ ❡✣❝✐❡♥t

✸✾ ✴ ✺✼

slide-104
SLIDE 104

▼❛s❦❡❞ ❊✈❡♥✲▼❛♥s♦✉r ✭MEM✮

  • MEM ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪✿

m c ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 ◦ P(Nk)

P

  • ϕi ❛r❡ ✜①❡❞ ▲❋❙❘s✱ (α, β, γ, N) ✐s t✇❡❛❦ ✭s✐♠♣❧✐✜❡❞✮
  • ❈♦♠❜✐♥❡s ❛❞✈❛♥t❛❣❡s ♦❢✿
  • P♦✇❡r✐♥❣✲✉♣ ♠❛s❦✐♥❣
  • ❲♦r❞✲❜❛s❡❞ ▲❋❙❘s
  • ❙✐♠♣❧❡r✱ ❝♦♥st❛♥t✲t✐♠❡ ✭❜② ❞❡❢❛✉❧t✮✱ ♠♦r❡ ❡✣❝✐❡♥t

✸✾ ✴ ✺✼

slide-105
SLIDE 105

MEM✿ ❉❡s✐❣♥ ❈♦♥s✐❞❡r❛t✐♦♥s

  • P❛rt✐❝✉❧❛r❧② s✉✐t❡❞ ❢♦r ❧❛r❣❡ st❛t❡s ✭♣❡r♠✉t❛t✐♦♥s✮
  • ▲♦✇ ♦♣❡r❛t✐♦♥ ❝♦✉♥ts ❜② ❝❧❡✈❡r ❝❤♦✐❝❡ ♦❢ ▲❋❙❘

❙❛♠♣❧❡ ▲❋❙❘s ✭st❛t❡ s✐③❡ ❛s ✇♦r❞s ♦❢ ❜✐ts✮✿

✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳

❲♦r❦ ❡①❝❡♣t✐♦♥❛❧❧② ✇❡❧❧ ❢♦r ❆❘❳ ♣r✐♠✐t✐✈❡s

✹✵ ✴ ✺✼

slide-106
SLIDE 106

MEM✿ ❉❡s✐❣♥ ❈♦♥s✐❞❡r❛t✐♦♥s

  • P❛rt✐❝✉❧❛r❧② s✉✐t❡❞ ❢♦r ❧❛r❣❡ st❛t❡s ✭♣❡r♠✉t❛t✐♦♥s✮
  • ▲♦✇ ♦♣❡r❛t✐♦♥ ❝♦✉♥ts ❜② ❝❧❡✈❡r ❝❤♦✐❝❡ ♦❢ ▲❋❙❘
  • ❙❛♠♣❧❡ ▲❋❙❘s ✭st❛t❡ s✐③❡ b ❛s n ✇♦r❞s ♦❢ w ❜✐ts✮✿

b w n ϕ 128 8 16 (x1, . . . , x15, (x0 ≪ 1) ⊕ (x9 ≫ 1) ⊕ (x10 ≪ 1)) 128 32 4 (x1, . . . , x3, (x0 ≪ 5) ⊕ x1 ⊕ (x1 ≪ 13)) 128 64 2 (x1, (x0 ≪ 11) ⊕ x1 ⊕ (x1 ≪ 13)) 256 64 4 (x1, . . . , x3, (x0 ≪ 3) ⊕ (x3 ≫ 5)) 512 32 16 (x1, . . . , x15, (x0 ≪ 5) ⊕ (x3 ≫ 7)) 512 64 8 (x1, . . . , x7, (x0 ≪ 29) ⊕ (x1 ≪ 9)) 1024 64 16 (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13)) 1600 32 50 (x1, . . . , x49, (x0 ≪ 3) ⊕ (x23 ≫ 3)) ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳

❲♦r❦ ❡①❝❡♣t✐♦♥❛❧❧② ✇❡❧❧ ❢♦r ❆❘❳ ♣r✐♠✐t✐✈❡s

✹✵ ✴ ✺✼

slide-107
SLIDE 107

MEM✿ ❉❡s✐❣♥ ❈♦♥s✐❞❡r❛t✐♦♥s

  • P❛rt✐❝✉❧❛r❧② s✉✐t❡❞ ❢♦r ❧❛r❣❡ st❛t❡s ✭♣❡r♠✉t❛t✐♦♥s✮
  • ▲♦✇ ♦♣❡r❛t✐♦♥ ❝♦✉♥ts ❜② ❝❧❡✈❡r ❝❤♦✐❝❡ ♦❢ ▲❋❙❘
  • ❙❛♠♣❧❡ ▲❋❙❘s ✭st❛t❡ s✐③❡ b ❛s n ✇♦r❞s ♦❢ w ❜✐ts✮✿

b w n ϕ 128 8 16 (x1, . . . , x15, (x0 ≪ 1) ⊕ (x9 ≫ 1) ⊕ (x10 ≪ 1)) 128 32 4 (x1, . . . , x3, (x0 ≪ 5) ⊕ x1 ⊕ (x1 ≪ 13)) 128 64 2 (x1, (x0 ≪ 11) ⊕ x1 ⊕ (x1 ≪ 13)) 256 64 4 (x1, . . . , x3, (x0 ≪ 3) ⊕ (x3 ≫ 5)) 512 32 16 (x1, . . . , x15, (x0 ≪ 5) ⊕ (x3 ≫ 7)) 512 64 8 (x1, . . . , x7, (x0 ≪ 29) ⊕ (x1 ≪ 9)) 1024 64 16 (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13)) 1600 32 50 (x1, . . . , x49, (x0 ≪ 3) ⊕ (x23 ≫ 3)) ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳

  • ❲♦r❦ ❡①❝❡♣t✐♦♥❛❧❧② ✇❡❧❧ ❢♦r ❆❘❳ ♣r✐♠✐t✐✈❡s

✹✵ ✴ ✺✼

slide-108
SLIDE 108

MEM✿ ❯♥✐q✉❡♥❡ss ♦❢ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐✈❡❧②✱ ♠❛s❦✐♥❣ ❣♦❡s ✇❡❧❧ ❛s ❧♦♥❣ ❛s

ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′

❢♦r ❛♥② (α, β, γ) = (α′, β′, γ′)

  • ❈❤❛❧❧❡♥❣❡✿ s❡t ♣r♦♣❡r ❞♦♠❛✐♥ ❢♦r (α, β, γ)
  • ❘❡q✉✐r❡s ❝♦♠♣✉t❛t✐♦♥ ♦❢ ❞✐s❝r❡t❡ ❧♦❣❛r✐t❤♠s

✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹

s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪ r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱ ❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪

✹✶ ✴ ✺✼

slide-109
SLIDE 109

MEM✿ ❯♥✐q✉❡♥❡ss ♦❢ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐✈❡❧②✱ ♠❛s❦✐♥❣ ❣♦❡s ✇❡❧❧ ❛s ❧♦♥❣ ❛s

ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′

❢♦r ❛♥② (α, β, γ) = (α′, β′, γ′)

  • ❈❤❛❧❧❡♥❣❡✿ s❡t ♣r♦♣❡r ❞♦♠❛✐♥ ❢♦r (α, β, γ)
  • ❘❡q✉✐r❡s ❝♦♠♣✉t❛t✐♦♥ ♦❢ ❞✐s❝r❡t❡ ❧♦❣❛r✐t❤♠s

✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹

s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪ r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱ ❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪

✹✶ ✴ ✺✼

slide-110
SLIDE 110

MEM✿ ❯♥✐q✉❡♥❡ss ♦❢ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐✈❡❧②✱ ♠❛s❦✐♥❣ ❣♦❡s ✇❡❧❧ ❛s ❧♦♥❣ ❛s

ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′

❢♦r ❛♥② (α, β, γ) = (α′, β′, γ′)

  • ❈❤❛❧❧❡♥❣❡✿ s❡t ♣r♦♣❡r ❞♦♠❛✐♥ ❢♦r (α, β, γ)
  • ❘❡q✉✐r❡s ❝♦♠♣✉t❛t✐♦♥ ♦❢ ❞✐s❝r❡t❡ ❧♦❣❛r✐t❤♠s

✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹

s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪ r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱ ❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪

✹✶ ✴ ✺✼

slide-111
SLIDE 111

MEM✿ ❯♥✐q✉❡♥❡ss ♦❢ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐✈❡❧②✱ ♠❛s❦✐♥❣ ❣♦❡s ✇❡❧❧ ❛s ❧♦♥❣ ❛s

ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′

❢♦r ❛♥② (α, β, γ) = (α′, β′, γ′)

  • ❈❤❛❧❧❡♥❣❡✿ s❡t ♣r♦♣❡r ❞♦♠❛✐♥ ❢♦r (α, β, γ)
  • ❘❡q✉✐r❡s ❝♦♠♣✉t❛t✐♦♥ ♦❢ ❞✐s❝r❡t❡ ❧♦❣❛r✐t❤♠s

✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹

s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪

  • r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱

❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪

✹✶ ✴ ✺✼

slide-112
SLIDE 112

MEM✿ ❯♥✐q✉❡♥❡ss ♦❢ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐✈❡❧②✱ ♠❛s❦✐♥❣ ❣♦❡s ✇❡❧❧ ❛s ❧♦♥❣ ❛s

ϕγ

2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′

❢♦r ❛♥② (α, β, γ) = (α′, β′, γ′)

  • ❈❤❛❧❧❡♥❣❡✿ s❡t ♣r♦♣❡r ❞♦♠❛✐♥ ❢♦r (α, β, γ)
  • ❘❡q✉✐r❡s ❝♦♠♣✉t❛t✐♦♥ ♦❢ ❞✐s❝r❡t❡ ❧♦❣❛r✐t❤♠s

✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹

s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪

  • r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱

❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮

  • s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪

✹✶ ✴ ✺✼

slide-113
SLIDE 113

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❖PP

A0 A1 Aa–1 M0 M1 Md–1 ⊕Mi C1 C2 Cd T

ϕ0(L) ϕ0(L) ϕ1(L) ϕ1(L) ϕa–1(L) ϕa–1(L) ϕ2◦ϕ2

1◦ϕd–1(L)

ϕ2◦ϕ2

1◦ϕd–1(L)

ϕ2◦ϕ0(L) ϕ2◦ϕ1(L) ϕ2◦ϕd–1(L) ϕ2◦ϕ0(L) ϕ2◦ϕ1(L) ϕ2◦ϕd–1(L)

P P P P P P P

  • ❖✛s❡t P✉❜❧✐❝ P❡r♠✉t❛t✐♦♥ ✭❖PP✮
  • ●❡♥❡r❛❧✐③❛t✐♦♥ ♦❢ ❖❈❇✸✿
  • P❡r♠✉t❛t✐♦♥✲❜❛s❡❞
  • ▼♦r❡ ❡✣❝✐❡♥t ▼❊▼ ♠❛s❦✐♥❣
  • ❙❡❝✉r✐t② ❛❣❛✐♥st ♥♦♥❝❡✲r❡s♣❡❝t✐♥❣ ❛❞✈❡rs❛r✐❡s
  • ✵✳✺✺ ❝♣❜ ✇✐t❤ r❡❞✉❝❡❞✲r♦✉♥❞ ❇▲❆❑❊✷❜

✹✷ ✴ ✺✼

L = P(Nk) ϕ1 = ϕ ⊕ id, ϕ2 = ϕ2 ⊕ ϕ ⊕ id

slide-114
SLIDE 114

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ▼❘❖

A0 Aa–1 T0 Td–1 M0 Md–1

|A||M|

C1 Cd T

ϕ0(L) ϕ0(L) ϕa–1(L) ϕa–1(L) ϕ1◦ϕ0(L) ϕ1◦ϕ0(L) ϕ1◦ϕd–1(L) ϕ1◦ϕd–1(L) ϕ2

1(L)

ϕ2

1(L)

ϕ2(L) ϕ2(L) ϕ2(L)⊕M0 ϕ2(L)⊕Md–1

P P P P P P P

  • ▼✐s✉s❡✲❘❡s✐st❛♥t ❖PP ✭▼❘❖✮
  • ❋✉❧❧② ♥♦♥❝❡✲♠✐s✉s❡ r❡s✐st❛♥t ✈❡rs✐♦♥ ♦❢ ❖PP
  • ✶✳✵✻ ❝♣❜ ✇✐t❤ r❡❞✉❝❡❞✲r♦✉♥❞ ❇▲❆❑❊✷❜

✹✸ ✴ ✺✼

L = P(Nk) ϕ1 = ϕ ⊕ id, ϕ2 = ϕ2 ⊕ ϕ ⊕ id

slide-115
SLIDE 115

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣

  • ■♥t✉✐t✐♦♥
  • ❙t❛t❡ ♦❢ t❤❡ ❆rt
  • ■♠♣r♦✈❡❞ ❊✣❝✐❡♥❝②
  • ■♠♣r♦✈❡❞ ❙❡❝✉r✐t②

◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✹✹ ✴ ✺✼

slide-116
SLIDE 116

❳P❳

  • XPX ❜② ▼❡♥♥✐♥❦ ❬▼❡♥✶✻❪✿

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

  • (t11, t12, t21, t22) ❢r♦♠ s♦♠❡ t✇❡❛❦ s❡t T ⊆ ({0, 1}n)4
  • T ❝❛♥ ✭st✐❧❧✮ ❜❡ ❛♥② s❡t

❙❡❝✉r✐t② ♦❢ str♦♥❣❧② ❞❡♣❡♥❞s ♦♥ ❝❤♦✐❝❡ ♦❢

✶ ✏❲❡❛❦✑

✐♥s❡❝✉r❡

✷ ✏◆♦r♠❛❧✑

s✐♥❣❧❡✲❦❡② s❡❝✉r❡

✸ ✏❙tr♦♥❣✑

r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✺ ✴ ✺✼

slide-117
SLIDE 117

❳P❳

  • XPX ❜② ▼❡♥♥✐♥❦ ❬▼❡♥✶✻❪✿

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

  • (t11, t12, t21, t22) ❢r♦♠ s♦♠❡ t✇❡❛❦ s❡t T ⊆ ({0, 1}n)4
  • T ❝❛♥ ✭st✐❧❧✮ ❜❡ ❛♥② s❡t
  • ❙❡❝✉r✐t② ♦❢ XPX str♦♥❣❧② ❞❡♣❡♥❞s ♦♥ ❝❤♦✐❝❡ ♦❢ T

✶ ✏❲❡❛❦✑

✐♥s❡❝✉r❡

✷ ✏◆♦r♠❛❧✑

s✐♥❣❧❡✲❦❡② s❡❝✉r❡

✸ ✏❙tr♦♥❣✑

r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✺ ✴ ✺✼

slide-118
SLIDE 118

❳P❳

  • XPX ❜② ▼❡♥♥✐♥❦ ❬▼❡♥✶✻❪✿

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

  • (t11, t12, t21, t22) ❢r♦♠ s♦♠❡ t✇❡❛❦ s❡t T ⊆ ({0, 1}n)4
  • T ❝❛♥ ✭st✐❧❧✮ ❜❡ ❛♥② s❡t
  • ❙❡❝✉r✐t② ♦❢ XPX str♦♥❣❧② ❞❡♣❡♥❞s ♦♥ ❝❤♦✐❝❡ ♦❢ T

✶ ✏❲❡❛❦✑ T

− → ✐♥s❡❝✉r❡

✷ ✏◆♦r♠❛❧✑

s✐♥❣❧❡✲❦❡② s❡❝✉r❡

✸ ✏❙tr♦♥❣✑

r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✺ ✴ ✺✼

slide-119
SLIDE 119

❳P❳

  • XPX ❜② ▼❡♥♥✐♥❦ ❬▼❡♥✶✻❪✿

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

  • (t11, t12, t21, t22) ❢r♦♠ s♦♠❡ t✇❡❛❦ s❡t T ⊆ ({0, 1}n)4
  • T ❝❛♥ ✭st✐❧❧✮ ❜❡ ❛♥② s❡t
  • ❙❡❝✉r✐t② ♦❢ XPX str♦♥❣❧② ❞❡♣❡♥❞s ♦♥ ❝❤♦✐❝❡ ♦❢ T

✶ ✏❲❡❛❦✑ T

− → ✐♥s❡❝✉r❡

✷ ✏◆♦r♠❛❧✑ T

− → s✐♥❣❧❡✲❦❡② s❡❝✉r❡

✸ ✏❙tr♦♥❣✑

r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✺ ✴ ✺✼

slide-120
SLIDE 120

❳P❳

  • XPX ❜② ▼❡♥♥✐♥❦ ❬▼❡♥✶✻❪✿

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

  • (t11, t12, t21, t22) ❢r♦♠ s♦♠❡ t✇❡❛❦ s❡t T ⊆ ({0, 1}n)4
  • T ❝❛♥ ✭st✐❧❧✮ ❜❡ ❛♥② s❡t
  • ❙❡❝✉r✐t② ♦❢ XPX str♦♥❣❧② ❞❡♣❡♥❞s ♦♥ ❝❤♦✐❝❡ ♦❢ T

✶ ✏❲❡❛❦✑ T

− → ✐♥s❡❝✉r❡

✷ ✏◆♦r♠❛❧✑ T

− → s✐♥❣❧❡✲❦❡② s❡❝✉r❡

✸ ✏❙tr♦♥❣✑ T

− → r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✺ ✴ ✺✼

slide-121
SLIDE 121

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s ✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-122
SLIDE 122

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

m 0k ⊕ 0P(k) 0k ⊕ 0P(k)

P

(0, 0, 0, 0) ∈ T

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s ✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-123
SLIDE 123

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

m P(m) 0k ⊕ 0P(k) 0k ⊕ 0P(k)

P

(0, 0, 0, 0) ∈ T = ⇒ XPXk((0, 0, 0, 0), m) = P(m)

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s ✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-124
SLIDE 124

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

k 1k ⊕ 0P(k) 1k ⊕ 1P(k)

P

(0, 0, 0, 0) ∈ T = ⇒ XPXk((0, 0, 0, 0), m) = P(m) (1, 0, 1, 1) ∈ T = ⇒ XPXk((1, 0, 1, 1), 0) = k

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s ✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-125
SLIDE 125

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

3P(k) 1k ⊕ 0P(k) 0k ⊕ 2P(k)

P

(0, 0, 0, 0) ∈ T = ⇒ XPXk((0, 0, 0, 0), m) = P(m) (1, 0, 1, 1) ∈ T = ⇒ XPXk((1, 0, 1, 1), 0) = k (1, 0, 0, 2) ∈ T = ⇒ XPXk((1, 0, 0, 2), 0) = 3P(k)

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s ✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-126
SLIDE 126

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

3P(k) 1k ⊕ 0P(k) 0k ⊕ 2P(k)

P

(0, 0, 0, 0) ∈ T = ⇒ XPXk((0, 0, 0, 0), m) = P(m) (1, 0, 1, 1) ∈ T = ⇒ XPXk((1, 0, 1, 1), 0) = k (1, 0, 0, 2) ∈ T = ⇒ XPXk((1, 0, 0, 2), 0) = 3P(k) · · · · · · · · ·

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s ✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-127
SLIDE 127

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

3P(k) 1k ⊕ 0P(k) 0k ⊕ 2P(k)

P

(0, 0, 0, 0) ∈ T = ⇒ XPXk((0, 0, 0, 0), m) = P(m) (1, 0, 1, 1) ∈ T = ⇒ XPXk((1, 0, 1, 1), 0) = k (1, 0, 0, 2) ∈ T = ⇒ XPXk((1, 0, 0, 2), 0) = 3P(k) · · · · · · · · ·

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts

  • ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s

✐♥✈❛❧✐❞ ✐♥s❡❝✉r❡ ✈❛❧✐❞ s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-128
SLIDE 128

❳P❳✿ ❲❡❛❦ ❚✇❡❛❦s

3P(k) 1k ⊕ 0P(k) 0k ⊕ 2P(k)

P

(0, 0, 0, 0) ∈ T = ⇒ XPXk((0, 0, 0, 0), m) = P(m) (1, 0, 1, 1) ∈ T = ⇒ XPXk((1, 0, 1, 1), 0) = k (1, 0, 0, 2) ∈ T = ⇒ XPXk((1, 0, 0, 2), 0) = 3P(k) · · · · · · · · ·

✏❱❛❧✐❞✑ ❚✇❡❛❦ ❙❡ts

  • ❚❡❝❤♥✐❝❛❧ ❞❡✜♥✐t✐♦♥ t♦ ❡❧✐♠✐♥❛t❡ ✇❡❛❦ ❝❛s❡s
  • T ✐♥✈❛❧✐❞ ⇐

⇒ XPX ✐♥s❡❝✉r❡

  • T ✈❛❧✐❞ ⇐

⇒ XPX s✐♥❣❧❡✲ ♦r r❡❧❛t❡❞✲❦❡② s❡❝✉r❡

✹✻ ✴ ✺✼

slide-129
SLIDE 129

❳P❳ ❈♦✈❡rs ❊✈❡♥✲▼❛♥s♦✉r

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

− − →

m c k k

P

❢♦r T = {(1, 0, 1, 0)} ❙✐♥❣❧❡✲❦❡② ❙❚P❘P s❡❝✉r❡ ✭s✉r♣r✐s❡❄✮

  • ❡♥❡r❛❧❧②✱ ✐❢

✱ ✐s ❛ ♥♦r♠❛❧ ❜❧♦❝❦❝✐♣❤❡r

✹✼ ✴ ✺✼

slide-130
SLIDE 130

❳P❳ ❈♦✈❡rs ❊✈❡♥✲▼❛♥s♦✉r

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

− − →

m c k k

P

❢♦r T = {(1, 0, 1, 0)}

  • ❙✐♥❣❧❡✲❦❡② ❙❚P❘P s❡❝✉r❡ ✭s✉r♣r✐s❡❄✮
  • ❡♥❡r❛❧❧②✱ ✐❢

✱ ✐s ❛ ♥♦r♠❛❧ ❜❧♦❝❦❝✐♣❤❡r

✹✼ ✴ ✺✼

slide-131
SLIDE 131

❳P❳ ❈♦✈❡rs ❊✈❡♥✲▼❛♥s♦✉r

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

− − →

m c k k

P

❢♦r T = {(1, 0, 1, 0)}

  • ❙✐♥❣❧❡✲❦❡② ❙❚P❘P s❡❝✉r❡ ✭s✉r♣r✐s❡❄✮
  • ●❡♥❡r❛❧❧②✱ ✐❢ |T | = 1✱ XPX ✐s ❛ ♥♦r♠❛❧ ❜❧♦❝❦❝✐♣❤❡r

✹✼ ✴ ✺✼

slide-132
SLIDE 132

❳P❳ ❈♦✈❡rs ❳❊❳ ❲✐t❤ ❊✈❡♥✲▼❛♥s♦✉r

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

− − →

m c (2α3β7γ ⊕ 1)k ⊕ 2α3β7γP(k)

P

❢♦r T = ( 2α3β7γ ⊕ 1 , 2α3β7γ , ( 2α3β7γ ⊕ 1 , 2α3β7γ )

  • (α, β, γ) ∈ {XEX✲t✇❡❛❦s}
  • (α, β, γ) ✐s ✐♥ ❢❛❝t t❤❡ ✏r❡❛❧✑ t✇❡❛❦

❘❡❧❛t❡❞✲❦❡② ❙❚P❘P s❡❝✉r❡ ✭✐❢ ✮

✹✽ ✴ ✺✼

slide-133
SLIDE 133

❳P❳ ❈♦✈❡rs ❳❊❳ ❲✐t❤ ❊✈❡♥✲▼❛♥s♦✉r

m c t11k ⊕ t12P(k) t21k ⊕ t22P(k)

P

− − →

m c (2α3β7γ ⊕ 1)k ⊕ 2α3β7γP(k)

P

❢♦r T = ( 2α3β7γ ⊕ 1 , 2α3β7γ , ( 2α3β7γ ⊕ 1 , 2α3β7γ )

  • (α, β, γ) ∈ {XEX✲t✇❡❛❦s}
  • (α, β, γ) ✐s ✐♥ ❢❛❝t t❤❡ ✏r❡❛❧✑ t✇❡❛❦
  • ❘❡❧❛t❡❞✲❦❡② ❙❚P❘P s❡❝✉r❡ ✭✐❢ 2α3β7γ = 1✮

✹✽ ✴ ✺✼

slide-134
SLIDE 134

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

A1 A2 Aa−1 Aa M1 M2 Md M1⊕···⊕Md C1 C2 Cd T

33L 2·33L 2a-233L 2a-134L L 3L 2·3L 2d-13L 2d-132L 2L 22L 2dL 2d-17L

Ek Ek Ek Ek Ek Ek Ek Ek Ek Ek Ek Ek

  • ❇② ❆♥❞r❡❡✈❛ ❡t ❛❧✳ ✭✷✵✶✹✮
  • ■♠♣❧✐❝✐t❧② ❜❛s❡❞ ♦♥ XEX ❜❛s❡❞ ♦♥ ❆❊❙

Prøst✲❈❖P❆ ❜② ❑❛✈✉♥ ❡t ❛❧✳ ✭✷✵✶✹✮✿ ❈❖P❆ ❜❛s❡❞ ♦♥ ❳❊❳ ❜❛s❡❞ ♦♥ ❊✈❡♥✲▼❛♥s♦✉r

✹✾ ✴ ✺✼

L = Ek(0)

slide-135
SLIDE 135

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

A1 A2 Aa−1 Aa M1 M2 Md M1⊕···⊕Md C1 C2 Cd T

33L 2·33L 2a-233L 2a-134L L 3L 2·3L 2d-13L 2d-132L 2L 22L 2dL 2d-17L

Ek Ek Ek Ek Ek Ek Ek Ek Ek Ek Ek Ek

  • ❇② ❆♥❞r❡❡✈❛ ❡t ❛❧✳ ✭✷✵✶✹✮
  • ■♠♣❧✐❝✐t❧② ❜❛s❡❞ ♦♥ XEX ❜❛s❡❞ ♦♥ ❆❊❙
  • Prøst✲❈❖P❆ ❜② ❑❛✈✉♥ ❡t ❛❧✳ ✭✷✵✶✹✮✿

❈❖P❆ ❜❛s❡❞ ♦♥ ❳❊❳ ❜❛s❡❞ ♦♥ ❊✈❡♥✲▼❛♥s♦✉r

✹✾ ✴ ✺✼

L = Ek(0)

slide-136
SLIDE 136

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ ❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

s❦

✳ ✳ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s ✳ ✳ ❈❖P❆

r❦

✳ ✳

r❦

✳ ✳

r❦

✳ ✳

✺✵ ✴ ✺✼

r❦

slide-137
SLIDE 137

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

s❦

✳ ✳ P ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s ✳ ✳ ❈❖P❆

r❦

✳ ✳

r❦

✳ ✳

r❦

✳ ✳

✺✵ ✴ ✺✼

r❦

slide-138
SLIDE 138

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

O

  • σ2

2n

− − − →

s❦

✳ ✳ P ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s ✳ ✳ ❈❖P❆

r❦

✳ ✳

r❦

✳ ✳

r❦

✳ ✳

✺✵ ✴ ✺✼

r❦

slide-139
SLIDE 139

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

O

  • σ2

2n

− − − →

s❦

✳ ✳ P ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ ❈❖P❆

  • ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s

✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

r❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

r❦

✳ ✳ E

r❦

✳ ✳

✺✵ ✴ ✺✼

r❦

slide-140
SLIDE 140

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

O

  • σ2

2n

− − − →

s❦

✳ ✳ P ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆

  • ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s

✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

r❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

r❦

✳ ✳ E

r❦

✳ ✳ P

✺✵ ✴ ✺✼

r❦

slide-141
SLIDE 141

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

O

  • σ2

2n

− − − →

s❦

✳ ✳ P ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆

  • ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s

✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

r❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

r❦

✳ ✳ E

  • 1

− − − →

r❦

✳ ✳ P

✺✵ ✴ ✺✼

r❦

slide-142
SLIDE 142

❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ❈❖P❆ ❛♥❞ Prøst✲❈❖P❆

❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆ ✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

s❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

s❦

✳ ✳ E

O

  • σ2

2n

− − − →

s❦

✳ ✳ P ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t② ♦❢ Prøst✲❈❖P❆

  • ❊①✐st✐♥❣ ♣r♦♦❢ ❣❡♥❡r❛❧✐③❡s

✳ ✳ ❈❖P❆

O

  • σ2

2n

− − − →

r❦

✳ ✳ XEX

O

  • σ2

2n

− − − →

r❦

✳ ✳ E

  • 1

− − − →

r❦

✳ ✳ P

✺✵ ✴ ✺✼

O

  • σ2

2n

  • r❦
slide-143
SLIDE 143

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣ ◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✺✶ ✴ ✺✼

slide-144
SLIDE 144
  • ✉❛r❛♥t❡❡✐♥❣ ❯♥✐q✉❡♥❡ss ♦❢ ◆♦♥❝❡

❝♦✉♥t❡r ♥♦♥❝❡ r❛♥❞♦♠ ♥♦♥❝❡ ✉s❡r✲❝❤♦s❡♥ ♥♦♥❝❡ ← − − − ← − − − ← − − − ■ss✉❡s ✇✐t❤ ♥♦♥❝❡ ❣❡♥❡r❛t✐♦♥✿

❈♦✉♥t❡r ♥❡❡❞s st♦r❛❣❡ ◆❡❡❞ s②♥❝❤r♦♥✐③❛t✐♦♥ ♦r tr❛♥s♠✐ss✐♦♥ ❊✣❝✐❡♥❝② ❝♦st ▲❛③✐♥❡ss ♦r ♠✐st❛❦❡ ♦❢ ✐♠♣❧❡♠❡♥t♦r ✳ ✳ ✳

❙♦♠❡t✐♠❡s✱ ❛tt❛❝❦❡r ❝❛♥ ✉s❡ s❛♠❡ ♥♦♥❝❡ ♠✉❧t✐♣❧❡ t✐♠❡s

✺✷ ✴ ✺✼

slide-145
SLIDE 145
  • ✉❛r❛♥t❡❡✐♥❣ ❯♥✐q✉❡♥❡ss ♦❢ ◆♦♥❝❡

❝♦✉♥t❡r ♥♦♥❝❡ r❛♥❞♦♠ ♥♦♥❝❡ ✉s❡r✲❝❤♦s❡♥ ♥♦♥❝❡ ← − − − ← − − − ← − − −

  • ■ss✉❡s ✇✐t❤ ♥♦♥❝❡ ❣❡♥❡r❛t✐♦♥✿
  • ❈♦✉♥t❡r ♥❡❡❞s st♦r❛❣❡
  • ◆❡❡❞ s②♥❝❤r♦♥✐③❛t✐♦♥ ♦r tr❛♥s♠✐ss✐♦♥
  • ❊✣❝✐❡♥❝② ❝♦st
  • ▲❛③✐♥❡ss ♦r ♠✐st❛❦❡ ♦❢ ✐♠♣❧❡♠❡♥t♦r
  • ✳ ✳ ✳

❙♦♠❡t✐♠❡s✱ ❛tt❛❝❦❡r ❝❛♥ ✉s❡ s❛♠❡ ♥♦♥❝❡ ♠✉❧t✐♣❧❡ t✐♠❡s

✺✷ ✴ ✺✼

slide-146
SLIDE 146
  • ✉❛r❛♥t❡❡✐♥❣ ❯♥✐q✉❡♥❡ss ♦❢ ◆♦♥❝❡

❝♦✉♥t❡r ♥♦♥❝❡ r❛♥❞♦♠ ♥♦♥❝❡ ✉s❡r✲❝❤♦s❡♥ ♥♦♥❝❡ ← − − − ← − − − ← − − −

  • ■ss✉❡s ✇✐t❤ ♥♦♥❝❡ ❣❡♥❡r❛t✐♦♥✿
  • ❈♦✉♥t❡r ♥❡❡❞s st♦r❛❣❡
  • ◆❡❡❞ s②♥❝❤r♦♥✐③❛t✐♦♥ ♦r tr❛♥s♠✐ss✐♦♥
  • ❊✣❝✐❡♥❝② ❝♦st
  • ▲❛③✐♥❡ss ♦r ♠✐st❛❦❡ ♦❢ ✐♠♣❧❡♠❡♥t♦r
  • ✳ ✳ ✳
  • ❙♦♠❡t✐♠❡s✱ ❛tt❛❝❦❡r ❝❛♥ ✉s❡ s❛♠❡ ♥♦♥❝❡ ♠✉❧t✐♣❧❡ t✐♠❡s

✺✷ ✴ ✺✼

slide-147
SLIDE 147

◆♦♥❝❡✲❘❡✉s❡ ✐♥ Pr❛❝t✐❝❡

◆♦♥❝❡✲❉✐sr❡s♣❡❝t✐♥❣ ❆❞✈❡rs❛r✐❡s✿ Pr❛❝t✐❝❛❧ ❋♦r❣❡r② ❆tt❛❝❦s ♦♥ ●❈▼ ✐♥ ❚▲❙

❇ö❝❦ ❡t ❛❧✳✱ ❯❙❊◆■❳ ❲❖❖❚ ✷✵✶✻

  • ●❈▼ ✐s ✇✐❞❡❧② ✉s❡❞ ❛✉t❤❡♥t✐❝❛t❡❞ ❡♥❝r②♣t✐♦♥ s❝❤❡♠❡
  • ❯s❡❞ ✐♥ ❚▲❙ ✭✏❤tt♣s✑✮
  • ■♥t❡r♥❡t✲✇✐❞❡ s❝❛♥ ❢♦r ●❈▼ ✐♠♣❧❡♠❡♥t❛t✐♦♥s
  • ✶✽✹ ❞❡✈✐❝❡s ✇✐t❤ ❞✉♣❧✐❝❛t❡❞ ♥♦♥❝❡s
  • ❱■❙❆✱ P♦❧✐s❤ ❜❛♥❦✱ ●❡r♠❛♥ st♦❝❦ ❡①❝❤❛♥❣❡✱ ✳ ✳ ✳
  • ≈ ✼✵✳✵✵✵ ❞❡✈✐❝❡s ✇✐t❤ r❛♥❞♦♠ ♥♦♥❝❡

✺✸ ✴ ✺✼

slide-148
SLIDE 148

❘❡s✐st❛♥❝❡ ❆❣❛✐♥st ◆♦♥❝❡✲❘❡✉s❡

■♥t✉✐t✐♦♥

  • ❆❧❧ ✐♥♣✉t s❤♦✉❧❞ ❜❡ ❝r②♣t♦❣r❛♣❤✐❝❛❧❧② tr❛♥s❢♦r♠❡❞
  • ❆♥② ❝❤❛♥❣❡ ✐♥ (N, A, M) −

→ ✉♥♣r❡❞✐❝t❛❜❧❡ (C, T)

  • ❖❢t❡♥ ❝♦♠❡s ❛t ❛ ♣r✐❝❡✿
  • ❊✣❝✐❡♥❝②
  • ❙❡❝✉r✐t②
  • P❛r❛❧❧❡❧✐③❛❜✐❧✐t②
  • ✳ ✳ ✳

✺✹ ✴ ✺✼

slide-149
SLIDE 149

❇❛❝❦ t♦ ●❈▼✲❙■❱

N

N

(K, L) T +0 T +1 T +(m−1) M1 M2 Mm

C1 C2 Cm A

T EK EK EK EK GHASHL KeyGenEk KEY ENC MAC

✺✺ ✴ ✺✼

slide-150
SLIDE 150

❖✉t❧✐♥❡

  • ❡♥❡r✐❝ ❈♦♠♣♦s✐t✐♦♥

▲✐♥❦ ❲✐t❤ ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❇❛s❡❞ ♦♥ ▼❛s❦✐♥❣ ◆♦♥❝❡✲❘❡✉s❡ ❈♦♥❝❧✉s✐♦♥

✺✻ ✴ ✺✼

slide-151
SLIDE 151

❈♦♥❝❧✉s✐♦♥

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

  • ◆♦♥❝❡✲❜❛s❡❞ ❆❊✿ ❝✉rr❡♥t❧② t❤❡ ♥♦r♠
  • ❈❈▼✱ ●❈▼✱ ❖❈❇✸✱ ✳ ✳ ✳
  • ◆♦♥❝❡✲r❡✉s❡ ❝♦♠❡s ❛t ❡✣❝✐❡♥❝② ♣❡♥❛❧t②
  • ●❈▼✲❙■❱✱ ▼❘❖✱ ❆❊❩✱ ✳ ✳ ✳
  • ❈❆❊❙❆❘ ❝♦♠♣❡t✐t✐♦♥

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❆❧❧♦✇ ❢♦r ♠♦❞✉❧❛r ❛♥❞ ❝♦♠♣❛❝t ♣r♦♦❢s ❇✐rt❤❞❛②✲❜♦✉♥❞ s❡❝✉r❡ ❚❇❈s✿ s✐♠♣❧❡ ❛♥❞ ❡✣❝✐❡♥t ❙❡❝✉r✐t② ❜❡②♦♥❞ t❤❡ ❜✐rt❤❞❛② ❜♦✉♥❞❄

❚❤❛♥❦ ②♦✉ ❢♦r ②♦✉r ❛tt❡♥t✐♦♥✦

✺✼ ✴ ✺✼

slide-152
SLIDE 152

❈♦♥❝❧✉s✐♦♥

❆✉t❤❡♥t✐❝❛t❡❞ ❊♥❝r②♣t✐♦♥

  • ◆♦♥❝❡✲❜❛s❡❞ ❆❊✿ ❝✉rr❡♥t❧② t❤❡ ♥♦r♠
  • ❈❈▼✱ ●❈▼✱ ❖❈❇✸✱ ✳ ✳ ✳
  • ◆♦♥❝❡✲r❡✉s❡ ❝♦♠❡s ❛t ❡✣❝✐❡♥❝② ♣❡♥❛❧t②
  • ●❈▼✲❙■❱✱ ▼❘❖✱ ❆❊❩✱ ✳ ✳ ✳
  • ❈❆❊❙❆❘ ❝♦♠♣❡t✐t✐♦♥

❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs

  • ❆❧❧♦✇ ❢♦r ♠♦❞✉❧❛r ❛♥❞ ❝♦♠♣❛❝t ♣r♦♦❢s
  • ❇✐rt❤❞❛②✲❜♦✉♥❞ s❡❝✉r❡ ❚❇❈s✿ s✐♠♣❧❡ ❛♥❞ ❡✣❝✐❡♥t
  • ❙❡❝✉r✐t② ❜❡②♦♥❞ t❤❡ ❜✐rt❤❞❛② ❜♦✉♥❞❄

❚❤❛♥❦ ②♦✉ ❢♦r ②♦✉r ❛tt❡♥t✐♦♥✦

✺✼ ✴ ✺✼

slide-153
SLIDE 153

❙❯PP❖❘❚■◆● ❙▲■❉❊❙

✺✽ ✴ ✺✼

slide-154
SLIDE 154

❉❡t❛✐❧❡❞ P✐❝t✉r❡ ♦❢ ●❈▼

n ⊞1 n + 1 ⊞1 n + 2 Ek Ek Ek m0 c0 m1 c1 ⊗H ⊗H ad ⊗H ⊗H t

❧❡♥(ad)❧❡♥(c)

Ek H

✺✾ ✴ ✺✼

slide-155
SLIDE 155

❉❡t❛✐❧❡❞ P✐❝t✉r❡ ♦❢ ●❈▼✲❙■❱

ad ⊗k1 ⊗k1 m0 ⊗k1 m1 ⊗k1

❧❡♥(ad)❧❡♥(m)

Ek2 n

✜①0

t t Ek2

✜①1

c0 ⊞1 Ek2

✜①1

c1 Ek Ek Ek Ek

  • ⊞1

⊞2 ⊞3 k1 k2

✻✵ ✴ ✺✼

slide-156
SLIDE 156

▼❊▼✿ ■♠♣❧❡♠❡♥t❛t✐♦♥

  • ❙t❛t❡ s✐③❡ b = 1024
  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • P✿ ❇▲❆❑❊✷❜ ♣❡r♠✉t❛t✐♦♥ ✇✐t❤ 4 ♦r 6 r♦✉♥❞s

▼❛✐♥ ✐♠♣❧❡♠❡♥t❛t✐♦♥ r❡s✉❧ts✿

♥♦♥❝❡✲r❡s♣❡❝t✐♥❣ ♠✐s✉s❡✲r❡s✐st❛♥t P❧❛t❢♦r♠ ❆❊❙✲●❈▼ ❖❈❇✸ ❉❡♦①②s ❖PP ❖PP

  • ❈▼✲❙■❱

❉❡♦①②s ▼❘❖ ▼❘❖ ❈♦rt❡①✲❆✽ ✸✽✳✻ ✷✽✳✾ ✲ ✹✳✷✻ ✺✳✾✶ ✲ ✲ ✽✳✵✼ ✶✶✳✸✷ ❙❛♥❞② ❇r✐❞❣❡ ✷✳✺✺ ✵✳✾✽ ✶✳✷✾ ✶✳✷✹ ✶✳✾✶ ✲ ✷✳✺✽ ✷✳✹✶ ✸✳✺✽ ❍❛s✇❡❧❧ ✶✳✵✸ ✵✳✻✾ ✵✳✾✻ ✵✳✺✺ ✵✳✼✺ ✶✳✶✼ ✶✳✾✷ ✶✳✵✻ ✶✳✸✾

✻✶ ✴ ✺✼

slide-157
SLIDE 157

▼❊▼✿ ■♠♣❧❡♠❡♥t❛t✐♦♥

  • ❙t❛t❡ s✐③❡ b = 1024
  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • P✿ ❇▲❆❑❊✷❜ ♣❡r♠✉t❛t✐♦♥ ✇✐t❤ 4 ♦r 6 r♦✉♥❞s
  • ▼❛✐♥ ✐♠♣❧❡♠❡♥t❛t✐♦♥ r❡s✉❧ts✿

♥♦♥❝❡✲r❡s♣❡❝t✐♥❣ ♠✐s✉s❡✲r❡s✐st❛♥t P❧❛t❢♦r♠ ❆❊❙✲●❈▼ ❖❈❇✸ ❉❡♦①②s= ❖PP4 ❖PP6

  • ❈▼✲❙■❱

❉❡♦①②s ▼❘❖ ▼❘❖ ❈♦rt❡①✲❆✽ ✸✽✳✻ ✷✽✳✾ ✲ ✹✳✷✻ ✺✳✾✶ ✲ ✲ ✽✳✵✼ ✶✶✳✸✷ ❙❛♥❞② ❇r✐❞❣❡ ✷✳✺✺ ✵✳✾✽ ✶✳✷✾ ✶✳✷✹ ✶✳✾✶ ✲ ✷✳✺✽ ✷✳✹✶ ✸✳✺✽ ❍❛s✇❡❧❧ ✶✳✵✸ ✵✳✻✾ ✵✳✾✻ ✵✳✺✺ ✵✳✼✺ ✶✳✶✼ ✶✳✾✷ ✶✳✵✻ ✶✳✸✾

✻✶ ✴ ✺✼

slide-158
SLIDE 158

▼❊▼✿ ■♠♣❧❡♠❡♥t❛t✐♦♥

  • ❙t❛t❡ s✐③❡ b = 1024
  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • P✿ ❇▲❆❑❊✷❜ ♣❡r♠✉t❛t✐♦♥ ✇✐t❤ 4 ♦r 6 r♦✉♥❞s
  • ▼❛✐♥ ✐♠♣❧❡♠❡♥t❛t✐♦♥ r❡s✉❧ts✿

♥♦♥❝❡✲r❡s♣❡❝t✐♥❣ ♠✐s✉s❡✲r❡s✐st❛♥t P❧❛t❢♦r♠ ❆❊❙✲●❈▼ ❖❈❇✸ ❉❡♦①②s= ❖PP4 ❖PP6

  • ❈▼✲❙■❱

❉❡♦①②s= ▼❘❖4 ▼❘❖6 ❈♦rt❡①✲❆✽ ✸✽✳✻ ✷✽✳✾ ✲ ✹✳✷✻ ✺✳✾✶ ✲ ✲ ✽✳✵✼ ✶✶✳✸✷ ❙❛♥❞② ❇r✐❞❣❡ ✷✳✺✺ ✵✳✾✽ ✶✳✷✾ ✶✳✷✹ ✶✳✾✶ ✲ ≈ ✷✳✺✽ ✷✳✹✶ ✸✳✺✽ ❍❛s✇❡❧❧ ✶✳✵✸ ✵✳✻✾ ✵✳✾✻ ✵✳✺✺ ✵✳✼✺ ✶✳✶✼ ≈ ✶✳✾✷ ✶✳✵✻ ✶✳✸✾

✻✶ ✴ ✺✼

slide-159
SLIDE 159

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13)) ❇❡❣✐♥ ✇✐t❤ st❛t❡ ♦❢ ✲❜✐t ✇♦r❞s P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-160
SLIDE 160

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • ❇❡❣✐♥ ✇✐t❤ st❛t❡ Li = [x0, . . . , x15] ♦❢ 64✲❜✐t ✇♦r❞s

x0 x1 x2 x3 x4 x5 x6 x7 x8 x9 x10 x11 x12 x13 x14 x15 P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-161
SLIDE 161

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • ❇❡❣✐♥ ✇✐t❤ st❛t❡ Li = [x0, . . . , x15] ♦❢ 64✲❜✐t ✇♦r❞s

x0 x1 x2 x3 x4 x5 x6 x7 x8 x9 x10 x11 x12 x13 x14 x15 x16

  • x16 = (x0 ≪ 53) ⊕ (x5 ≪ 13)

P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-162
SLIDE 162

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • ❇❡❣✐♥ ✇✐t❤ st❛t❡ Li = [x0, . . . , x15] ♦❢ 64✲❜✐t ✇♦r❞s

x0 x1 x2 x3 x4 x5 x6 x7 x8 x9 x10 x11 x12 x13 x14 x15 x16 x17

  • x16 = (x0 ≪ 53) ⊕ (x5 ≪ 13)
  • x17 = (x1 ≪ 53) ⊕ (x6 ≪ 13)

P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-163
SLIDE 163

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • ❇❡❣✐♥ ✇✐t❤ st❛t❡ Li = [x0, . . . , x15] ♦❢ 64✲❜✐t ✇♦r❞s

x0 x1 x2 x3 x4 x5 x6 x7 x8 x9 x10 x11 x12 x13 x14 x15 x16 x17 x18

  • x16 = (x0 ≪ 53) ⊕ (x5 ≪ 13)
  • x17 = (x1 ≪ 53) ⊕ (x6 ≪ 13)
  • x18 = (x2 ≪ 53) ⊕ (x7 ≪ 13)

P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-164
SLIDE 164

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • ❇❡❣✐♥ ✇✐t❤ st❛t❡ Li = [x0, . . . , x15] ♦❢ 64✲❜✐t ✇♦r❞s

x0 x1 x2 x3 x4 x5 x6 x7 x8 x9 x10 x11 x12 x13 x14 x15 x16 x17 x18 x19

  • x16 = (x0 ≪ 53) ⊕ (x5 ≪ 13)
  • x17 = (x1 ≪ 53) ⊕ (x6 ≪ 13)
  • x18 = (x2 ≪ 53) ⊕ (x7 ≪ 13)
  • x19 = (x3 ≪ 53) ⊕ (x8 ≪ 13)

P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-165
SLIDE 165

▼❊▼✿ P❛r❛❧❧❡❧✐③❛❜✐❧✐t②

  • ▲❋❙❘ ♦♥ 16 ✇♦r❞s ♦❢ 64 ❜✐ts✿

ϕ(x0, . . . , x15) = (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13))

  • ❇❡❣✐♥ ✇✐t❤ st❛t❡ Li = [x0, . . . , x15] ♦❢ 64✲❜✐t ✇♦r❞s

x0 x1 x2 x3 x4 x5 x6 x7 x8 x9 x10 x11 x12 x13 x14 x15 x16 x17 x18 x19

  • x16 = (x0 ≪ 53) ⊕ (x5 ≪ 13)
  • x17 = (x1 ≪ 53) ⊕ (x6 ≪ 13)
  • x18 = (x2 ≪ 53) ⊕ (x7 ≪ 13)
  • x19 = (x3 ≪ 53) ⊕ (x8 ≪ 13)
  • P❛r❛❧❧❡❧✐③❛❜❧❡ ✭❆❱❳✷✮ ❛♥❞ ✇♦r❞✲s❧✐❝❡❛❜❧❡

✻✷ ✴ ✺✼

slide-166
SLIDE 166

❳P❳✿ ❙✐♥❣❧❡✲❑❡② ❙❡❝✉r✐t②

✭❙tr♦♥❣✮ ❚✇❡❛❦❛❜❧❡ P❘P

IC

XPX(±)

k

P ±

  • π(±)

P ±

distinguisher D

  • ■♥❢♦r♠❛t✐♦♥✲t❤❡♦r❡t✐❝ ✐♥❞✐st✐♥❣✉✐s❤❛❜✐❧✐t②

π ✐❞❡❛❧ t✇❡❛❦❛❜❧❡ ♣❡r♠✉t❛t✐♦♥

  • P ✐❞❡❛❧ ♣❡r♠✉t❛t✐♦♥
  • k s❡❝r❡t ❦❡②

T ✐s ✈❛❧✐❞ = ⇒ XPX ✐s ✭❙✮❚P❘P ✉♣ t♦ O q2 + qr 2n

  • ✻✸ ✴ ✺✼
slide-167
SLIDE 167

❳P❳✿ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t②

❘❡❧❛t❡❞✲❑❡② ✭❙tr♦♥❣✮ ❚✇❡❛❦❛❜❧❡ P❘P

IC

XPX(±)

ϕ(k)

P ±

  • rkπ(±)

P ±

distinguisher D

  • ■♥❢♦r♠❛t✐♦♥✲t❤❡♦r❡t✐❝ ✐♥❞✐st✐♥❣✉✐s❤❛❜✐❧✐t②

rkπ ✐❞❡❛❧ t✇❡❛❦❛❜❧❡ r❡❧❛t❡❞✲❦❡② ♣❡r♠✉t❛t✐♦♥

  • P ✐❞❡❛❧ ♣❡r♠✉t❛t✐♦♥
  • k s❡❝r❡t ❦❡②
  • D r❡str✐❝t❡❞ t♦ s♦♠❡ s❡t ♦❢ ❦❡②✲❞❡r✐✈✐♥❣ ❢✉♥❝t✐♦♥s Φ

✻✹ ✴ ✺✼

slide-168
SLIDE 168

❳P❳✿ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t②

❑❡②✲❉❡r✐✈✐♥❣ ❋✉♥❝t✐♦♥s

  • Φ⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ

✿ ❛❧❧ ❢✉♥❝t✐♦♥s ♦r ◆♦t❡✿ ♠❛s❦✐♥❣s ✐♥ ❛r❡ ❘❡s✉❧ts

✐❢ ✐s ✈❛❧✐❞✱ ❛♥❞ ❢♦r ❛❧❧ t✇❡❛❦s✿ s❡❝✉r✐t② ❚P❘P ❛♥❞ ❙❚P❘P ❚P❘P ❙❚P❘P

✻✺ ✴ ✺✼

slide-169
SLIDE 169

❳P❳✿ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t②

❑❡②✲❉❡r✐✈✐♥❣ ❋✉♥❝t✐♦♥s

  • Φ⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ
  • ΦP⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ ♦r P(k) → P(k) ⊕ ǫ

◆♦t❡✿ ♠❛s❦✐♥❣s ✐♥ ❛r❡ ❘❡s✉❧ts

✐❢ ✐s ✈❛❧✐❞✱ ❛♥❞ ❢♦r ❛❧❧ t✇❡❛❦s✿ s❡❝✉r✐t② ❚P❘P ❛♥❞ ❙❚P❘P ❚P❘P ❙❚P❘P

✻✺ ✴ ✺✼

slide-170
SLIDE 170

❳P❳✿ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t②

❑❡②✲❉❡r✐✈✐♥❣ ❋✉♥❝t✐♦♥s

  • Φ⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ
  • ΦP⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ ♦r P(k) → P(k) ⊕ ǫ
  • ◆♦t❡✿ ♠❛s❦✐♥❣s ✐♥ XPX ❛r❡ ti1k ⊕ ti2P(k)

❘❡s✉❧ts

✐❢ ✐s ✈❛❧✐❞✱ ❛♥❞ ❢♦r ❛❧❧ t✇❡❛❦s✿ s❡❝✉r✐t② ❚P❘P ❛♥❞ ❙❚P❘P ❚P❘P ❙❚P❘P

✻✺ ✴ ✺✼

slide-171
SLIDE 171

❳P❳✿ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t②

❑❡②✲❉❡r✐✈✐♥❣ ❋✉♥❝t✐♦♥s

  • Φ⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ
  • ΦP⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ ♦r P(k) → P(k) ⊕ ǫ
  • ◆♦t❡✿ ♠❛s❦✐♥❣s ✐♥ XPX ❛r❡ ti1k ⊕ ti2P(k)

❘❡s✉❧ts

✐❢ T ✐s ✈❛❧✐❞✱ ❛♥❞ ❢♦r ❛❧❧ t✇❡❛❦s✿ s❡❝✉r✐t② Φ t12 = 0 ❚P❘P Φ⊕ t12, t22 = 0 ❛♥❞ (t21, t22) = (0, 1) ❙❚P❘P Φ⊕ ❚P❘P ❙❚P❘P

✻✺ ✴ ✺✼

slide-172
SLIDE 172

❳P❳✿ ❘❡❧❛t❡❞✲❑❡② ❙❡❝✉r✐t②

❑❡②✲❉❡r✐✈✐♥❣ ❋✉♥❝t✐♦♥s

  • Φ⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ
  • ΦP⊕✿ ❛❧❧ ❢✉♥❝t✐♦♥s k → k ⊕ δ ♦r P(k) → P(k) ⊕ ǫ
  • ◆♦t❡✿ ♠❛s❦✐♥❣s ✐♥ XPX ❛r❡ ti1k ⊕ ti2P(k)

❘❡s✉❧ts

✐❢ T ✐s ✈❛❧✐❞✱ ❛♥❞ ❢♦r ❛❧❧ t✇❡❛❦s✿ s❡❝✉r✐t② Φ t12 = 0 ❚P❘P Φ⊕ t12, t22 = 0 ❛♥❞ (t21, t22) = (0, 1) ❙❚P❘P Φ⊕ t11, t12 = 0 ❚P❘P ΦP ⊕ t11, t12, t21, t22 = 0 ❙❚P❘P ΦP ⊕

✻✺ ✴ ✺✼

slide-173
SLIDE 173

❳P❳✿ ❙❡❝✉r✐t② Pr♦♦❢ ❚❡❝❤♥✐q✉❡s

P❛t❛r✐♥✬s ❍✲❝♦❡✣❝✐❡♥t ❚❡❝❤♥✐q✉❡

  • ❊❛❝❤ ❝♦♥✈❡rs❛t✐♦♥ ❞❡✜♥❡s ❛ tr❛♥s❝r✐♣t
  • ❉❡✜♥❡ ❣♦♦❞ ❛♥❞ ❜❛❞ tr❛♥s❝r✐♣ts

❜❛❞ tr❛♥s❝r✐♣t ❢♦r ♣r♦❜✳ r❛t✐♦ ❢♦r ❣♦♦❞ tr❛♥s❝r✐♣ts ❚r❛❞❡✲♦✛✿ ❞❡✜♥❡ ❜❛❞ tr❛♥s❝r✐♣ts s♠❛rt❧②✦

✻✻ ✴ ✺✼

slide-174
SLIDE 174

❳P❳✿ ❙❡❝✉r✐t② Pr♦♦❢ ❚❡❝❤♥✐q✉❡s

P❛t❛r✐♥✬s ❍✲❝♦❡✣❝✐❡♥t ❚❡❝❤♥✐q✉❡

  • ❊❛❝❤ ❝♦♥✈❡rs❛t✐♦♥ ❞❡✜♥❡s ❛ tr❛♥s❝r✐♣t
  • ❉❡✜♥❡ ❣♦♦❞ ❛♥❞ ❜❛❞ tr❛♥s❝r✐♣ts

Advrk✲(s)prp

XPX

(D) ≤ ε + Pr

  • ❜❛❞ tr❛♥s❝r✐♣t ❢♦r (

rkπ, P)

  • ♣r♦❜✳ r❛t✐♦ ❢♦r ❣♦♦❞ tr❛♥s❝r✐♣ts

❚r❛❞❡✲♦✛✿ ❞❡✜♥❡ ❜❛❞ tr❛♥s❝r✐♣ts s♠❛rt❧②✦

✻✻ ✴ ✺✼

slide-175
SLIDE 175

❳P❳✿ ❙❡❝✉r✐t② Pr♦♦❢ ❚❡❝❤♥✐q✉❡s

P❛t❛r✐♥✬s ❍✲❝♦❡✣❝✐❡♥t ❚❡❝❤♥✐q✉❡

  • ❊❛❝❤ ❝♦♥✈❡rs❛t✐♦♥ ❞❡✜♥❡s ❛ tr❛♥s❝r✐♣t
  • ❉❡✜♥❡ ❣♦♦❞ ❛♥❞ ❜❛❞ tr❛♥s❝r✐♣ts

Advrk✲(s)prp

XPX

(D) ≤ ε + Pr

  • ❜❛❞ tr❛♥s❝r✐♣t ❢♦r (

rkπ, P)

  • ♣r♦❜✳ r❛t✐♦ ❢♦r ❣♦♦❞ tr❛♥s❝r✐♣ts
  • ❚r❛❞❡✲♦✛✿ ❞❡✜♥❡ ❜❛❞ tr❛♥s❝r✐♣ts s♠❛rt❧②✦

✻✻ ✴ ✺✼

slide-176
SLIDE 176

❳P❳✿ ❙❡❝✉r✐t② Pr♦♦❢ ❚❡❝❤♥✐q✉❡s

❇❡❢♦r❡ t❤❡ ■♥t❡r❛❝t✐♦♥

  • ❘❡✈❡❛❧ ✏❞❡❞✐❝❛t❡❞✑ ♦r❛❝❧❡ q✉❡r✐❡s

❆❢t❡r t❤❡ ■♥t❡r❛❝t✐♦♥

  • ❘❡✈❡❛❧ ❦❡② ✐♥❢♦r♠❛t✐♦♥
  • ❙✐♥❣❧❡✲❦❡②✿ k ❛♥❞ P(k)
  • Φ⊕✲r❡❧❛t❡❞✲❦❡②✿ k ❛♥❞ P(k ⊕ δ)
  • ΦP ⊕✲r❡❧❛t❡❞✲❦❡②✿ k ❛♥❞ P(k ⊕ δ) ❛♥❞ P −1(P(k) ⊕ ε)

❇♦✉♥❞✐♥❣ t❤❡ ❆❞✈❛♥t❛❣❡

  • ❙♠❛rt ❞❡✜♥✐t✐♦♥ ♦❢ ❜❛❞ tr❛♥s❝r✐♣ts

✻✼ ✴ ✺✼

slide-177
SLIDE 177

❳P❳✿ ❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ▼✐♥❛❧♣❤❡r

A1 A2 Aa−1 Aa M1 M2 Md−1 Md C1 C2 Cd−1 Cd T

2L′ 2L′ 22L′ 22L′ 2a-1L′ 2a-1L′ 2a-13L′ 2a-13L′ 2L 2L 23L 23L 22d-3L 22d-3L 22d-1L 22d-1L 22L 22L 24L 24L 22d-2L 22d-2L 22d-13L 22d-13L

P P P P P P P P P P P P

  • ❇② ❙❛s❛❦✐ ❡t ❛❧✳ ✭✷✵✶✹✮
  • ❊①tr❛ ♥♦♥❝❡ N ❝♦♥❝❛t❡♥❛t❡❞ t♦ k

❇❛s❡❞ ♦♥ ✇✐t❤ ✳ ✳ ▼✐♥❛❧♣❤✳

r❦

✳ ✳

r❦

✳ ✳

✻✽ ✴ ✺✼

L′ = kflag0 ⊕ P(kflag0) L = kflagN ⊕ P(kflagN)

slide-178
SLIDE 178

❳P❳✿ ❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ▼✐♥❛❧♣❤❡r

A1 A2 Aa−1 Aa M1 M2 Md−1 Md C1 C2 Cd−1 Cd T

2L′ 2L′ 22L′ 22L′ 2a-1L′ 2a-1L′ 2a-13L′ 2a-13L′ 2L 2L 23L 23L 22d-3L 22d-3L 22d-1L 22d-1L 22L 22L 24L 24L 22d-2L 22d-2L 22d-13L 22d-13L

P P P P P P P P P P P P

  • ❇② ❙❛s❛❦✐ ❡t ❛❧✳ ✭✷✵✶✹✮
  • ❊①tr❛ ♥♦♥❝❡ N ❝♦♥❝❛t❡♥❛t❡❞ t♦ k
  • ❇❛s❡❞ ♦♥ XPX ✇✐t❤ T = {(2α3β, 2α3β, 2α3β, 2α3β)}

✳ ✳ ▼✐♥❛❧♣❤✳

r❦

✳ ✳

r❦

✳ ✳

✻✽ ✴ ✺✼

L′ = kflag0 ⊕ P(kflag0) L = kflagN ⊕ P(kflagN)

slide-179
SLIDE 179

❳P❳✿ ❆♣♣❧✐❝❛t✐♦♥ t♦ ❆❊✿ ▼✐♥❛❧♣❤❡r

A1 A2 Aa−1 Aa M1 M2 Md−1 Md C1 C2 Cd−1 Cd T

2L′ 2L′ 22L′ 22L′ 2a-1L′ 2a-1L′ 2a-13L′ 2a-13L′ 2L 2L 23L 23L 22d-3L 22d-3L 22d-1L 22d-1L 22L 22L 24L 24L 22d-2L 22d-2L 22d-13L 22d-13L

P P P P P P P P P P P P

  • ❇② ❙❛s❛❦✐ ❡t ❛❧✳ ✭✷✵✶✹✮
  • ❊①tr❛ ♥♦♥❝❡ N ❝♦♥❝❛t❡♥❛t❡❞ t♦ k
  • ❇❛s❡❞ ♦♥ XPX ✇✐t❤ T = {(2α3β, 2α3β, 2α3β, 2α3β)}

✳ ✳ ▼✐♥❛❧♣❤✳

O

  • σ2

2n

− − − →

r❦

✳ ✳ XPX

O

  • σ2

2n

− − − →

r❦

✳ ✳ P

✻✽ ✴ ✺✼

L′ = kflag0 ⊕ P(kflag0) L = kflagN ⊕ P(kflagN)