Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Computer Network & Security Expert

Question 1 -

Consider the following protocol for two parties A and B to flip a fair coin.

1. A trusted party T publishes her public key pk;

2. Then A chooses a uniform bit bA, encrypts it using pk, an announces the ciphertext cA to B and T;

3. Next, B acts symmetrically and announces a ciphertext cB ≠ cA;

4. T decrypts both cA and cB, and the parties XOR the results to obtain the value of the coin.

  • Argue that even if A is dishonest (but B is honest), the final value of the coin is uniformly distributed.
  • Assume the parties use EI Gamal encryption (where the bit b is encoded as the group element gb before being encrypted - note that efficient decryption is still possible). Show how a dishonest B can bias the coin to any values he likes.
  • Suggest what type of encryption scheme would be appropriate to use here. Can you define an appropriate notion of security for a fair coin flipping and prove that the above coin flipping protocol achieves this definition when using an appropriate encryption scheme?

Question 2 -

Suppose three users have RSA public keys (N1, 3), (N2, 3), and (N3, 3) (i.e., they all use e =3), with N1 < N2 < N3. Consider the following method for sending the same message m ∈ {0, 1}l to each of these parties: choose a uniform r ← ZN_1, and send to everyone the same ciphertext

< [r3 mod N1], [r3 mod N2], [r3 mod N3], H(r) ⊕ m >                          (1)

where H : ZN_1 → {0, 1}l. Assume l >> n

  • Show that this is not CPA-secure, and an adversary can recover m from the ciphertext even when H is modeled as a random oracle.
  • Show a simple way to fix this and get a CPA-secure method that transmits a ciphertext of length 3l + O(n).

Question 3 -

Secret sharing is a problem in cryptography where n shares X1, ..., Xn (called shadows) are given to n parties where some of the shadows or all of them are needed in order to reconstruct the secret (M) which is a number (i.e. there is a specified threshold t, such that any t shadows make it possible to compute M which is a bit string). Consider the following secret sharing algorithm:

1. Choose at random t-1 positive integers a1, ..., at-1 with ai < P (P is a prime number) and let a0 = M.

2. Build the polynomial f(x) = a0 + a1x + a2x2 + a3x3 + .... + at-1xt-1.

3. Create n shadows that are: (1, f(1)( mod p)), ...,(n, f(n)( mod p)) (i.e. every participant is given a point (an integer input to the polynomial, and the corresponding integer output).

Note: Suppose t < P - 1

Based on the above protocol, answer the following questions:

Part 1 - In above protocol, arithmetic is all modulo p to build the polynomial. Suppose that we mistakenly calculate the shadows as (x, f(x)) instead of (x, f(x)( mod p)), can an eavesdropper gain information from M or not if the eavesdropper sees some of the points (e.g. Suppose the eavesdropper finds (1,f(1)) or (2, f(2)))? If your answer is no, please prove it otherwise provide an example that shows the eavesdropper can gain information about M.

Part 2 - Suppose we modify the scheme such that M = a0 + a1 +. . .+ at-1 mod p. Does having t or more shadows make it possible to compute M? Does having fewer than t shadows reveal nothing about M? Please justify your answers.

Question 4 -

A strong one-time secure signature scheme satisfies the following: given a signature σ' on a message m', it is infeasible to output (m, σ) ≠ (m', σ') for which σ is a valid signature on m (note that m = m' is allowed)

  • Give a formal definition of strong one-time secure signatures.
  • Assuming the existence of one-way functions, show a one-way function for which Lamport's scheme is not a strong one-time secure signature scheme.
  • Construct a strong one-time secure signature scheme based on any assumption use in the book.

Hint: Use a particular one-way function in Lamport's signature.

Computer Network & Security, Computer Science

  • Category:- Computer Network & Security
  • Reference No.:- M92275460
  • Price:- $65

Guranteed 36 Hours Delivery, In Price:- $65

Have any Question?


Related Questions in Computer Network & Security

If a firms total cost function is given byt c

If a firm's total cost function is given byT C= 115,000Q-500Q2+Q3, what range of output does the firm have economies of scale?

Data communications and networks assignment -aim a library

Data Communications and Networks Assignment - Aim: A library research and industry related project is to be carried out on a topic of your choice. The project topic must be related to Data Communications and Networking. ...

With smaller companies saving thousands and larger

With smaller companies saving thousands and larger companies saving billions through flexible manufacturing, if you are a discrete parts manufacturer seeking to be more lean, it is important to consider whether this migh ...

Assignment wireless applications advances advantages and

Assignment : Wireless Applications, Advances, Advantages, and Disadvantages The adoption of wireless technologies varies from one industry to another, and is often based on the benefits provided versus the challenges, im ...

There are standards in network communication through which

There are standards in network communication through which data is transferred from one system to another. Discuss why these standards are important. Do you think it would be easier to purchase different equipment and so ...

Wireless networks and security assignment - design and

Wireless Networks and Security Assignment - Design and implementation of secure enterprise wireless network Purpose of the assessment - The purpose of this assignment is to design and implement a secure enterprise wirele ...

Describe 2 variables a government will look at to predict

Describe 2 variables a government will look at to predict where the economy will be in the next six months.

The software company niksoft is selling a new defense

The software company NikSoft is selling a new defense against DDoS attacks. Their software looks at the source IP address on all incoming packets, and if it finds any IP address that accounts for more than 1% of traffic ...

Sms use short message peer to peer smpp protocolimessage

SMS use Short Message Peer to Peer (SMPP) protocol IMessage based on Apple push notifications (APNS) - binary protocol WhatsApp uses standard Extensible Messaging and Presence Protocol (XMPP) Write a pragraph explaining ...

Question in regards to encryption does the public key and

Question : In regards to encryption, does the public key and private key come from the sender or does the receiver already have the private and is given the public key by the sender? The response must be typed, single sp ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As