❇❡②♦♥❞ ❇✐rt❤❞❛②✲❇♦✉♥❞ ❙❡❝✉r✐t②
❇❛rt ▼❡♥♥✐♥❦ ❘❛❞❜♦✉❞ ❯♥✐✈❡rs✐t② ✭❚❤❡ ◆❡t❤❡r❧❛♥❞s✮
❙✉♠♠❡r s❝❤♦♦❧ ♦♥ r❡❛❧✲✇♦r❧❞ ❝r②♣t♦ ❛♥❞ ♣r✐✈❛❝② ❏✉♥❡ ✽✱ ✷✵✶✼
✶ ✴ ✸✷
rt rt rt - - PowerPoint PPT Presentation
rt rt rt rst trs r s
✶ ✴ ✸✷
✷ ✴ ✸✷
✷ ✴ ✸✷
✷ ✴ ✸✷
blockcipher random permutation
✸ ✴ ✸✷
blockcipher random permutation
✸ ✴ ✸✷
blockcipher random permutation
✸ ✴ ✸✷
blockcipher random permutation
E (D) =
random function
F (D) =
✺ ✴ ✸✷
CTR[E](σ) ≤ Advprp E (σ) +
✺ ✴ ✸✷
CTR[E](σ) ≤ Advprp E (σ) +
✺ ✴ ✸✷
✻ ✴ ✸✷
CTR[E](σ)
✻ ✴ ✸✷
✼ ✴ ✸✷
CTR[F](σ) ≤ Advprf F (σ)
✼ ✴ ✸✷
CTR[F](σ) ≤ Advprf F (σ)
✼ ✴ ✸✷
✽ ✴ ✸✷
✾ ✴ ✸✷
✾ ✴ ✸✷
✾ ✴ ✸✷
✶✵ ✴ ✸✷
✶✶ ✴ ✸✷
✶✷ ✴ ✸✷
✶✸ ✴ ✸✷
✶✸ ✴ ✸✷
✶✸ ✴ ✸✷
blockcipher random function
✶✹ ✴ ✸✷
blockcipher random function
E (q) ≤ Advprp E (q) +
✶✹ ✴ ✸✷
✶✺ ✴ ✸✷
1· 0·
✶✺ ✴ ✸✷
1· 0·
✶✺ ✴ ✸✷
1· 0·
XoP(q) ≤ Advprp E (2q) + q/2n
✶✺ ✴ ✸✷
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](σ) ≤ Advprf XoP(σ)
✶✻ ✴ ✸✷
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](σ) ≤ Advprf XoP(σ)
E (2σ) + σ/2n
✶✻ ✴ ✸✷
0n+1 1n+1 0n+2 1n+2 0n+ℓ 1n+ℓ
CTR[XoP](σ) ≤ Advprf XoP(σ)
E (2σ) + σ/2n
✶✻ ✴ ✸✷
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✶✼ ✴ ✸✷
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✶✼ ✴ ✸✷
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✶✼ ✴ ✸✷
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✶✼ ✴ ✸✷
0n+1 1n+1 0n+1 1n+2 0n+1 1n+w 0n+2 1n+w+1
✶✼ ✴ ✸✷
✶✽ ✴ ✸✷
✶✽ ✴ ✸✷
✶✾ ✴ ✸✷
✶✾ ✴ ✸✷
✶✾ ✴ ✸✷
✶✾ ✴ ✸✷
Pa1 =Pa2 Pb1 Pb3 Pa4 =Pa5 Pb5 Pb2 =Pa3 =Pb4
λ1 λ2 λ3 λ4 λ5
Pa6 Pb6
λ6
Pa7 Pb7
λ7
Pa8 Pa9 Pb8 =Pb9 =Pb10 =Pa11 Pa10 Pb11
λ8 λ9 λ10 λ11 ✷✵ ✴ ✸✷
✷✶ ✴ ✸✷
λ1 λ2
✷✶ ✴ ✸✷
λ1 λ2
✷✶ ✴ ✸✷
λ1 λ2
✷✶ ✴ ✸✷
λ1 λ2
✷✶ ✴ ✸✷
λ1 λ2
✷✷ ✴ ✸✷
λ1 λ2
✷✷ ✴ ✸✷
λ1 λ2
✷✷ ✴ ✸✷
λ1 λ2
✷✷ ✴ ✸✷
λ1 λ2
✷✷ ✴ ✸✷
λ1 λ2
✷✸ ✴ ✸✷
λ1 λ2 λ3
✷✸ ✴ ✸✷
λ1 λ2 λ3
✷✸ ✴ ✸✷
λ1 λ2 λ3
Pa1 = Pb5 Pb1 = Pa2 Pb2 = Pa3 Pb3 = Pa4 Pb4 = Pa5
λ1 λ2 λ3 λ4 λ5
Pa1 =Pa2 Pb1 Pa3 =Pa4 Pb4 = Pa5 Pb2 =Pb3
λ1 λ2 λ3 λ4
Pa8 Pb7 = Pb8
λ1 ⊕ λ2 ⊕ · · · ⊕ λ7
Pb5 = Pa6 Pb6 = Pb7
λ6 λ5 λ7 ✷✹ ✴ ✸✷
✷✺ ✴ ✸✷
1· 0·
✷✻ ✴ ✸✷
1· 0·
✷✻ ✴ ✸✷
1· 0·
✷✻ ✴ ✸✷
1· 0·
✷✻ ✴ ✸✷
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
✷✼ ✴ ✸✷
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
✷✼ ✴ ✸✷
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
2nq
✷✼ ✴ ✸✷
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
✷✽ ✴ ✸✷
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
✷✽ ✴ ✸✷
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
✷✽ ✴ ✸✷
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
1 2nq
✷✽ ✴ ✸✷
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
1 2nq
✷✽ ✴ ✸✷
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
1 (2n)2q
1 2nq
XoP(q) ≤ q/2n
✷✽ ✴ ✸✷
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
✷✾ ✴ ✸✷
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
✷✾ ✴ ✸✷
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
2nq
✷✾ ✴ ✸✷
Pa1 Pb1 Pb2 Pb3 Pbw
y1 y2 y3 y
w
Pa2 Pbw+1 Pbw+2 Pbw+3 Pb2w
yw+1 yw+2 yw+3 y
2 w
· · · Paq/w Pbq✕w+1 Pbq✕w+2 Pbq✕w+3 Pbq
yq✕w+1 yq✕w+2 yq✕w+3 y
q
2nq
CENC(q) ≤ q/2n + wq/2n+1
✷✾ ✴ ✸✷
h(m)
✸✵ ✴ ✸✷
✸✶ ✴ ✸✷
✸✷ ✴ ✸✷
✸✸ ✴ ✸✷
✸✹ ✴ ✸✷
✸✹ ✴ ✸✷
✸✹ ✴ ✸✷
✸✺ ✴ ✸✷
✸✺ ✴ ✸✷
✸✺ ✴ ✸✷
✸✺ ✴ ✸✷
✸✻ ✴ ✸✷
✸✻ ✴ ✸✷
✸✻ ✴ ✸✷
blockcipher random function
E (D) +
2
✸✼ ✴ ✸✷
✸✽ ✴ ✸✷
✸✽ ✴ ✸✷
✸✽ ✴ ✸✷
E (D) ❜② ❞❡✜♥✐t✐♦♥
✸✽ ✴ ✸✷
E (D) ❜② ❞❡✜♥✐t✐♦♥
✸✽ ✴ ✸✷
✸✾ ✴ ✸✷
$
∪
✸✾ ✴ ✸✷
$
∪
$
✸✾ ✴ ✸✷
$
∪
$
$
∪
$
✸✾ ✴ ✸✷
$
∪
$
$
∪
$
✹✵ ✴ ✸✷
$
∪
$
$
∪
$
✹✵ ✴ ✸✷
$
∪
$
$
∪
$
✹✵ ✴ ✸✷
$
∪
$
$
∪
$
✹✵ ✴ ✸✷
$
∪
$
$
∪
$
2)
2n
✹✵ ✴ ✸✷
✹✶ ✴ ✸✷
✹✶ ✴ ✸✷
✹✶ ✴ ✸✷
✹✶ ✴ ✸✷
✹✶ ✴ ✸✷
✹✷ ✴ ✸✷
✹✷ ✴ ✸✷
✹✷ ✴ ✸✷
✹✷ ✴ ✸✷
✹✸ ✴ ✸✷
k
✹✹ ✴ ✸✷
k
✹✹ ✴ ✸✷
k
✹✹ ✴ ✸✷
k
✹✹ ✴ ✸✷
k
✹✺ ✴ ✸✷
k
✹✺ ✴ ✸✷
k
E
k , P ±; p±, P ±) ≤ 2QT
✹✻ ✴ ✸✷
Pr[(E±
k ,P ±) ❣✐✈❡s τ]
Pr[(p±,P ±) ❣✐✈❡s τ] ≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
✹✼ ✴ ✸✷
✹✽ ✴ ✸✷
✹✽ ✴ ✸✷
✹✽ ✴ ✸✷
k , P ±)✿ ❦❡② ✉s❡❞ ❢♦r ❡♥❝r②♣t✐♦♥
✹✽ ✴ ✸✷
k , P ±)✿ ❦❡② ✉s❡❞ ❢♦r ❡♥❝r②♣t✐♦♥
$
✹✽ ✴ ✸✷
✹✾ ✴ ✸✷
✹✾ ✴ ✸✷
✹✾ ✴ ✸✷
✹✾ ✴ ✸✷
✹✾ ✴ ✸✷
♦❢ s✐③❡
✺✵ ✴ ✸✷
♦❢ s✐③❡
✺✵ ✴ ✸✷
✺✵ ✴ ✸✷
✺✵ ✴ ✸✷
✺✵ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
✺✶ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
✺✶ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±)✿
k , P ±) ❣✐✈❡s τ
✺✶ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±)✿
k , P ±) ❣✐✈❡s τ
✺✶ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±)✿
k , P ±) ❣✐✈❡s τ
✺✶ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±)✿
k , P ±) ❣✐✈❡s τ
✺✶ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±) ❣✐✈❡s τ
(2n−Q−T)! 2n·2n! (2n−Q)!(2n−T)! 2n·(2n!)2
✺✷ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±) ❣✐✈❡s τ
(2n−Q−T)! 2n·2n! (2n−Q)!(2n−T)! 2n·(2n!)2
✺✷ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±) ❣✐✈❡s τ
(2n−Q−T)! 2n·2n! (2n−Q)!(2n−T)! 2n·(2n!)2
✺✷ ✴ ✸✷
Pr
k ,P ±) ❣✐✈❡s τ
≥ 1 − ε ✭∀ ❣♦♦❞ τ✮
k , P ±) ❣✐✈❡s τ
(2n−Q−T)! 2n·2n! (2n−Q)!(2n−T)! 2n·(2n!)2
E
k , P ±; p±, P ±) ≤ 2QT
✺✷ ✴ ✸✷