Fake - c1 DK (c'1) XOR (Attack XOR IV) c1 XOR IV XOR Attack c1 XOR Attack
Fake - c1 DK (c'1) XOR (Attack XOR IV) c1 XOR IV XOR Attack c1 XOR Attack
1n
2n/2
XOR
x1,x2
2n/2
h(x3)=1n
h(x3)
x3
2n
1/2n
Ek
m2=x2||x1 m1=x1||x2
x2
x1
K=x1 XOR x2 for both m1,m2.
Hk(m1)=Ek(x1) XOR Ek(x2)=Ek(x2) XOR Ek(x1)=Hk(m2).
x1||x2
Attack
MAC error
Attack
padding error
7-i
i
i
i-1
MacError
padding
MacError
padding error
MAC
CyberSecEx4 Page 1