17
6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup claim) RSA Making RSA IND-CCA2 secure (OAEP) Other aspects of RSA security 1

Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

  • Upload
    others

  • View
    6

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

6.857 Computer and Network Security Lecture 14

Admin:

Problem Set #4 out Today:

Malleability of El Gamal IND-CCA2 security (Cramer-Shoup claim) RSA Making RSA IND-CCA2 secure (OAEP) Other aspects of RSA security

1

Page 2: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

rrr

._T

_-

z_

_44:

——

••—

‘—-.0

-;—

---I

“:—

—-—

-

a

i_]r,

.--‘-

4-

1-I-

-‘

>%

>-

rr:t

±.s

HH

-;—

---:-

---t--t-

33

11.

•-

——

.—

(31’

-

#1!

1C

q)j

F,

‘3

-•

IL1I

I-s-_fl

11-

2

Page 3: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

IC

CI

H

p.

-•1-•

4Q

j-

—-i--

—----I

.1----,-

-fp

.:

•-L

-4”

Ct

:—--;

4—

q•4

F2

•I

5•_•..•;

.;._

.

•-:

r

S..

tJff—

-*1

+--

4*10

•---

--

p.,•

-F

4

“4•

.••4

—.

c_s

I

.....j

‘tJr---

f-----1-

-i.L

._.

.-

.4),

C4,

S

i9’iL)

‘p.1

.—

,

3

Page 4: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

-.—

.—--—

——

——

—-—

-----—

—---—

——

—--—

-—

.——

-—

——

—.—

——

—C

-—

:

I—

H?1

F -.1--

‘0>

içj:

9)I-

-

-*

<I

-.

L.

H_

zt:

V4

J’

•!:4

:.t

:ztz

:z.z

:-!

:z:’

.r

--

-:

--r

—::

4k

4

Page 5: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

__

-—

__

H

4

I-—

--—

—-

---—

—--

--

-II

______

_________

-—

—-T

—-

r—

--—

-—

-‘-r

--—

-—

jJt4

:z.

±I

•r4-j.

c9?

HtJ

riH

ztV

:‘

xt

I4’-

...

,..

t:.H

z‘.

ZZ

li-

-

Z::

:t

;—

--

-—

_?

..--;_

-1

---

--.-

—---

--

-‘--—

—--

—t

Iz

--

-fL

-.

-

--

--

-

—1-

If

3••

I__-

1—

—--

—--

--r-

j--

—‘-

—-v

--i—

-.

‘-ç-r-:

-:---

HI

C—

-I

H—

—-—

1-——

——

v-—-

---

--

—_ct

5

Page 6: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

j

-V

----

----

--

t-

I1

‘ii

riH

:t-r-

HE

*r

1p

rC

-

êb

I.

---

—.

•+

•-

1*:

T-

r-

V-.

H—

4_-A

—-r

-

II’-”

L-

-.

-I.

__

<-•

J.i***

r-----I

-•-

r1

t,7

\

I•

$,

L.

r1

I-

‘—1

IYT

(N•r

-.

•-

—.

-‘I

tU

(NN

4--—

—-

--‘

•I

——

--

-L±

-—

-

.4--

-H4.

--

C

+

6

Page 7: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

rr

—T

’I

flt—ii:

L_

L

+—

-4-H-h--

44

..j4

+,

-t

4g

-

H-

t

LI

-

‘2—t

Ht-.1

II

tiltttE

tI

H-

——

——

——

1I

-L-4---J-

-J

—H

mfr

•1--

-I

F-

fl-I.

L

z

I

L.t.

ErT

:Jt

.t-T

--t-rht+

..-±

tL

1C

S

rE

ilfl’

Ht-

Tn

--

-f-ti-I

Ft

:pt±tZ

t4T

:‘—

4!

I

_____

bLhhHht

Jj

7

Page 8: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

-

-

1j-J---

--‘

I_-

r---j

-1--

44

5

liz: -

;:‘:.

—.

-f-—

----—

’—t—

H’ ‘-

a—

C

Ia

—I--

4

L

HH

Ht

t-4

—k-

--j

4—

1‘--—

i$

ILH

HLt

—t--

L_--%

%.

*-i

+-

Ca

—---—

---

Hzz

zt-

——

——

3L

II

L—

_a-,—

—-

44

TI’

fT1

-_

__

,%

._

—_

4H

TII

1 --1 I :1 1

8

Page 9: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

ii’LW

-

-

tzP

r3’”L

’uo;i

‘3

1-—

a—

°p

,

fl-ç

4;

H&

14

,,

—12.o

I-

-

-.-

.,-

.,

.B

‘-—

--•

I•

-I

•-

•I

•.,

‘—

FI

•a’

I-

-_

a.,-

5-

:i

-:

xii

t‘“

:‘

in‘-‘‘

-.-.L

:*

:fl

-

g••_

••••••

..

.

-.

.-r

’-

—at

.

--.

-,t-

;r

rL

-...

-‘---

-

1:)-

1--

-

iw-

:1Lj

J-I

.•

I—

-.

-•

_..

•y

.L

-,r

-

9

Page 10: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

*‘F

TH

-n

y.

,-4-—

4—

3-.-4..I

•..n

•-

--

J[

I.

-.-.±

..-

j-

t-I

——

1c

t

—I

2.,

.n

.i_

L4L

J—

°ji-I

3-

----

10....k

4”

—-

Sa)

r”

4r

j-

‘nj

4-

It

-

4I

E€

,

-J‘z.-.-

=•

=

4-.••

t•..#

a-

HflH4°t

LIE

4,

-t---

SS

4’E

H-

Cl

‘4’

IC’

---

riri

—,

—Ii

ft0

—-

$+-—

—-

—4

•.1

.-

C•

eL.

•t

.•

-•

‘•

—c.

‘v{

a

-4

1)1

7zzzz:

II;

-I.

—-—--

—•-

--

—-—

—-

I

10

Page 11: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

I

f

°:-

vt!

V.

—a.

--—

—.-

-t(I

i

tr

r-

33a

t_&

-I

it0

I

11

i’.

I[ç:

rd

Lk1

r3

3:ç

41

H±tL

LtcJ

-

aH

1:

t

7(“7

.‘?k..t..-

r-—

{H

iJ’

fli

r-..

r-’

I—

TJI

._,I

I

‘_

4a.Z

Jh1!7

kF1

——

Y-

—-

----1

%—

--

--

,-

--

-----_

-I

--—

——

——

—--

-t

4J

-—

--

I.

Ii

j_

__

_—

’—

--_

--3.

__..

____i_

__._

__

—_

I_

__

-_

__

_I,._

11

Page 12: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

I—

,-

--c

--.

-—

2-1

-.-fl’-1

I-

II

--

---‘---,

--

.-

‘I

[4

--

I

s-

—.

,—

--

I-

‘-r

I1

---t1

±—

--

4?-,±

--4

---

-

-2

0-

-i

iJiil

:‘it

is°

I

IC

at

-C

jr-

I

1-t!

Itj

:13:

_e

4-

L4

4eIL

1*.

-

4—---,

—---e

-H

i:tI S3

U’S

I.1-t

1-tI

-—C

’3

SC

>___t

.‘:t:•3

‘S-6

12

Page 13: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

- —%-----‘,ret.’t-- —-..-, _-_-

I

iZJ.n++± t-r-t-t H*1

—----t--.

rT*t.synini’trt tvcly$ipA [BR V1]

p be ti%n 1

g1jnnnj irit 1(0JHQ t

LjFL

T L.I

- I-

- —‘— - -I iII-’--r--4.- -

Lizta1LuP tt*

r - -,--t

[ ,—--:‘ j— 1 -4-----.-- -

-- LL+++J _ --— -

±r4tft1z;:rtrttri t:____

‘V - ‘--p--t4-”i I

13

Page 14: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

• ‘ ‘‘ ‘‘‘ ‘‘‘

- - -rz:: zzzzz

__

—-—- -.------- :: HL1

-• - 1- —4 -L—._I

ri :i *piJ4i4LS

j-; +-

[t: tt

_____

-

E E z°4On aecryptrfL t!RcA -

L

- -! â4’ W 0” nè- present

- L

14

Page 15: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

—4 4 I

I4

t:tJZ

4ti

jrT

7rrttr

-

--

it

:t:7

l_

zs

tThfI

J±J1

I

1‘

w-t

31

r‘I

z:;rb

Ejz

tH :

-r

t--u

-I

i

i-I

3L

_.t’.?

afr

’1e

r1

‘r—

3r- 4r-”

.011fl1

--

r-‘-—

•I

IT —

t—

---

—--—

I—

-—

-L

--

L

15

Page 16: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

-‘r-rr-,4

-—

-T

----—

-‘r

--

—-

II

--

--

-“

L---1--iJH

1.--.--H

:•--

-L“c

-I1--*

)-J

----fi

--t’-----*

-fr

.----:

.-4

a,;r

J—--

°--

C-—

-.1_

10

IC

——I

s-—

i-1--

-:*I

it

‘‘‘

E

it

L.c’—

“i”

--r-—

—“

-..

:4

;-—:-t

--

Sa

r-i

-+

r————--ii

--4--

!-s-_;-

-.-

1--

•1

‘-

‘r

1--’---

--H

r

16

Page 17: Network and Computer Security, Lecture 14 · 6.857 Computer and Network Security Lecture 14 Admin: Problem Set #4 out Today: Malleability of El Gamal IND-CCA2 security (Cramer-Shoup

MIT OpenCourseWarehttp://ocw.mit.edu

6.857 Network and Computer SecuritySpring 2014

For information about citing these materials or our Terms of Use, visit: http://ocw.mit.edu/terms.