Menu

(Solved) : Consider Following Modified Version Padded Rsa Encryption Assume Messages Encrypted Length Q29335085 . . .

Cryptology question:

Consider the following modified version of padded RSA encryption: Assume messages to be encrypted have length exactly IIN /2. To encrypt, first compute m := 0x0??0x001m where r is a uniform string of length ||N1l/2 - 16. Then compute the ciphertext c[modN]. When decrypting a ci- phertext c, the receiver computes m[cmodN] and returns an error of m does not consist of 0z00 followed by ||N1l/2 - 16 arbitrary bits followed by 0r00. Show that this scheme is not CCA-secure. Why is it easier to construct a chosen-ciphertext attack on this scheme than on PKCS #1 v1.5?

Consider the following modified version of padded RSA encryption: Assume messages to be encrypted have length exactly IIN /2. To encrypt, first compute m := 0x0??0x001m where r is a uniform string of length ||N1l/2 – 16. Then compute the ciphertext c[modN]. When decrypting a ci- phertext c, the receiver computes m[cmodN] and returns an error of m does not consist of 0z00 followed by ||N1l/2 – 16 arbitrary bits followed by 0r00. Show that this scheme is not CCA-secure. Why is it easier to construct a chosen-ciphertext attack on this scheme than on PKCS #1 v1.5? Show transcribed image text

Expert Answer


Answer to Consider Following Modified Version Padded Rsa Encryption Assume Messages Encrypted Length Q29335085 . . .

OR