Slide 19
Slide 19 text
Point-and-Permute
Enca1,,b1,
(c1
)
Enca1,,b0
(c0
)
Enca0,,b1
(c0
)
Enca0,b0
(c0
)
Beaver, Micali and Rogaway [STOC 1990]
Select random bit for each wire: rw
Set last bit of w0
to rw
, w1
to ¬ra
Order table canonically: 00/01/10/11
ra
= 1, rb
= 1