Back
ExamFull examExam paper only

2016 09 28

Full exam for Cryptography and Architectures for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Cryptography and Architectures for Computer Security Exam Code: 095947 (old 090959), A.Y. 2015–2016, Semester: 2 Prof. G. Pelosi September 28th, 2016 – Exam Session Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Surname: . . . . . . . . . . . . .

Cryptography and Architectures for Computer SecurityFull exam

Document information

What's included in this study material

Full exam for Cryptography and Architectures for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Cryptography and Architectures for Computer Security Exam Code: 095947 (old 090959), A.Y. 2015–2016, Semester: 2 Prof. G. Pelosi September 28th, 2016 – Exam Session Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Surname: . . . . . . . . . . . . .

Import quality: text was extracted directly from the original document.

Extracted content from the document

Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.

Page 1

Cryptography and Architectures for Computer Security Exam Code: 095947 (old 090959), A.Y. 2015–2016, Semester: 2 Prof. G. Pelosi September 28th, 2016 – Exam Session Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Surname: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Student ID: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Signature: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Time: 2h:30’. Use of textbooks, notes, phones or Internet connected devices is not allowed. Prior to turn in your paper, write your name on any additional sheet and sign it. Question 1 [2 pts] Alice uses a block cipher Enc having 64-bit block size and 64-bit key size. She is worried that the key size is too small to prevent brute force attacks. Therefore, she decides to improve the encryption scheme employing 2 independent 64-bit keys: (k0,k1), and encrypting her messages as: c = Enck0(m)⊕k1, m,c ∈{ 0, 1}64 • Assume that the adversary gets access to a few plaintext/ciphertext pairs and is indeed able to perform a brute-force attack on the original encryption scheme Enc and recover the key with a known plaintext attack . Show that he can also break the “improved” scheme and recover the Alice’s extended key. Solution: Considering 2 pairs of plaintexts and ciphertexts (m1,c 1), (m2,c 2) for each possible value of k0 compute k1 =c1⊕ Enck0(m1) and check if k1 =c2⊕ Enck0(m2) holds The adversary needs to compute every value of Enck0(m1) and Enck0(m2), thus the cost for obtaining the extended key with 128-bit is only doubled with respect to a bruteforce of the 64-bit key of the original cipher. Question 2 [3 pts] Consider a file encrypted with a given mode of operation and the…

Preview

First page of the document.

First page: 2016 09 28