By Thomas Baigneres, Pascal Junod, Yi Lu, Jean Monnerat, Serge Vaudenay

ISBN-10: 0387279342

ISBN-13: 9780387279343

ISBN-10: 038728835X

ISBN-13: 9780387288352

This spouse workout and answer ebook to A Classical advent to Cryptography: purposes for Communications protection incorporates a conscientiously revised model of educating fabric utilized by the authors and given as examinations to advanced-level scholars of the Cryptography and protection Lecture at EPFL from 2000 to mid-2005. A Classical creation to Cryptography workout BookÂ covers a majority of the themes that make up ultra-modern cryptology, together with symmetric or public-key cryptography, cryptographic protocols, layout, cryptanalysis, and implementation of cryptosystems. routines don't require an intensive history in arithmetic, because the most vital notions are brought and mentioned in lots of of the routines. The authors anticipate the readers to be pleased with uncomplicated evidence of discrete likelihood conception, discrete arithmetic, calculus, algebra, and laptop technology. Following the version of A Classical creation to Cryptography: purposes for Communications safeguard, routines on the topic of the extra complicated elements of the textbook are marked with a celeb.

The By symmetry, it is sufficient to compute this probability for R1. As R1 is not shifted if and only if TI # T2 = T3, we have pfixed 1 - 1 23 1 ~ T I + T ~ ==T-~ Ti 7 2 ,T3 4' 2. , 2 Clearly, either 2 or 3 LFSRs are shifted at each clock. In other words, when one LFSR is fixed, the two others are shifted. The probability that exactly two LFSRs are shifted is thus equal to the probability that exactly one is fixed. This probability is simply equal to plfiXed p2fixed p3fixed= as the three events are disjoint.

An,Xl,... , h e D Solution on page 53 EXERCISE BOOK Solutions Solution 1 Weak Keys of DES If the subkeys kl to k16 are equal, then the reversed and original key schedules are identical. In that case, DESk clearly is an involution. The sixteen subkeys will be equal when the registers C and D are all-zero or all-one bit vectors, as the rotation of such bitstrings has no effect on them. Therefore, the four weak keys of DES can easily be computed to the four possible combinations of these C and D by applying P C I - I values.

7. Attacking the CBCICBC-'ICBC-' mode of operation 1 Give an approximation of the complexity of Algorithm 3. $, lent to the condition P:" = P?. in Algorithm 3. )equiva- 4 Deduce an attack that recovers the value of K3. Once K3 is found, how can K1 and K2 be recovered? What is the overall complexity of the attack? " - D Exercise 13 Solution on page 47 *A Variant of A511 I In stream ciphers, the prevailing encryption is a bitwise XOR operation between the m-bit plaintext and the m-bit keystream which is the output of a so-called keystream generator fed by the L-bit secret key, where m is much larger than !.

A Classical Introduction to Cryptography Exercise Book by Thomas Baigneres, Pascal Junod, Yi Lu, Jean Monnerat, Serge Vaudenay

