Write a formula using the function symbol MAC(…) to indicate what is being authenticated. You may choose any reasonable variable names for the data items. b. Say an adversary is sitting between you and the retailer, with the ability to intercept traffic and send messages. Assume the authentication is not vulnerable to length extension. Describe a cryptographic attack the adversary could carry out to “max out” your credit card. What type of attack is this? c. What could the retailer do to prevent this attack, simply by changing what data is sent in that single encrypted, authenticated message? Write a new MAC() formula to show the new construction.

Database System Concepts
7th Edition
ISBN:9780078022159
Author:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Chapter1: Introduction
Section: Chapter Questions
Problem 1PE
icon
Related questions
Question
  1. You are placing an order with an online retailer. To complete a purchase, your web browser sends a single encrypted, MAC-authenticated message to the web site, consisting only of the following information: a) your credit card information, b) the item number and quantity being ordered.

a. Write a formula using the function symbol MAC(…) to indicate what is being authenticated. You may choose any reasonable variable names for the data items.

b. Say an adversary is sitting between you and the retailer, with the ability to intercept traffic and send messages. Assume the authentication is not vulnerable to length extension. Describe a cryptographic attack the adversary could carry out to “max out” your credit card. What type of attack is this?

c. What could the retailer do to prevent this attack, simply by changing what data is sent in that single encrypted, authenticated message? Write a new MAC() formula to show the new construction.

Expert Solution
steps

Step by step

Solved in 3 steps

Blurred answer
Knowledge Booster
Intelligent Machines
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, computer-science and related others by exploring similar questions and additional content below.
Similar questions
Recommended textbooks for you
Database System Concepts
Database System Concepts
Computer Science
ISBN:
9780078022159
Author:
Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:
McGraw-Hill Education
Starting Out with Python (4th Edition)
Starting Out with Python (4th Edition)
Computer Science
ISBN:
9780134444321
Author:
Tony Gaddis
Publisher:
PEARSON
Digital Fundamentals (11th Edition)
Digital Fundamentals (11th Edition)
Computer Science
ISBN:
9780132737968
Author:
Thomas L. Floyd
Publisher:
PEARSON
C How to Program (8th Edition)
C How to Program (8th Edition)
Computer Science
ISBN:
9780133976892
Author:
Paul J. Deitel, Harvey Deitel
Publisher:
PEARSON
Database Systems: Design, Implementation, & Manag…
Database Systems: Design, Implementation, & Manag…
Computer Science
ISBN:
9781337627900
Author:
Carlos Coronel, Steven Morris
Publisher:
Cengage Learning
Programmable Logic Controllers
Programmable Logic Controllers
Computer Science
ISBN:
9780073373843
Author:
Frank D. Petruzella
Publisher:
McGraw-Hill Education