Recall the (Randomised) Elgamal Cryptosystem - IT Assignment Help

Download Solution Order New Solution
Assignment Task

 

Question 1 Recall the (randomised) Elgamal cryptosystem. Let p be a prime. Let G be the group Z∗ p = f1; 2; : : : ; p - 1g under multiplication modulo p. Let g 2 G be a generator of the group. Let (x; h) denote Bob’s (private key, public key) pair, where x is a random element of Zp-1 = f0; 1; : : : ; p - 1g, and h ≡ gx (mod p).

(a) Suppose Alice sends a message m 2 G with ciphertext c = (c1; c2) to Bob, encrypted using a random k 2 Z p-1. Suppose Eve, the eavesdropper, comes to know both the message m, and its ciphertext

- Explain what can Eve do if Alice were to encrypt m0 2 G using the same k, resulting in ciphertext c0 = (c0 1; c0 2).
An encryption system is considered malleable if given a ciphertext of some unknown plaintext, it is possible to obtain a valid ciphertext of a related plaintext without even knowing the contents of the plaintext. This is problematic depending on the application. For instance, in bidding for a contract, a company might outbid its competitor by simply multiplying it’s rival company’s encrypted bid by 0.9, without even knowing the bid [DDN03]. The following questions relates to the malleability of the Elgamal cryptosystem taught in the lecture.

(b) Suppose we are given the ciphertext c = (c1; c2) of some unknown message m, where c1 ≡ gk (mod p) for some unknown random integer k 2 Zp-1 and c2 ≡ m · hk (mod p), where h is the public key of some unknown private key x, in the Elgamal cryptosystem. Let m0 be a message that you know. Can you obtain a valid ciphertext of the message m · m0 without knowing m?

Question 2
Let X be a random variable taking on n values with probabilities p1; p2; : : : ; pn. Recall from Lecture 9 that the min-entropy of X, denoted E1(X), is given by
E1(X) = min i 1 pi:
If X is uniformly distributed then p1 = p2 = · · · = pn = n1 .
(a) Show that if X is not uniformly distributed then necessarily one of the pi’s is > 1=n.
(b) Show that if X is not uniformly distributed then E1(X) < n.
(c) Argue that min-entropy is the highest if X is uniformly distributed. What is the minimum entropy in this case?

Question 3
Let H be a hash function that has the properties of hiding and collision-resistance. Recall that collision
resistance property means that it is infeasible to find two inputs x; y with x 6= y such that H(x) = H(y).
Consider the commitment scheme from Lecture 9. To commit to a message m, Alice samples a random nonce r, and computes C = H(rjjm);
and publishes C as her commitment. A commitment scheme is binding if it is infeasible to find two pairs (m; r) and (m0; r0) with m 6= m0 such that H(rjjm) = H(r0jjm0):
Show that if you can find a collision in H, this does not necessarily break the binding property of the commitment scheme.

 

This IT Assignment has been solved by our IT experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.