Talk:Existential forgery

From Wikipedia, the free encyclopedia

Sorry for being thick, but I think the current definition makes no sense at all.

First, I can always create a valid (sigma,m) where "m has not been MACed in the past by the legitimate MAC [user]". Do we not need in the definition some sigma' (the original sigma thata forger wants to forge)?

Secondly, are there any constraints on the key used? I.e. will the original user generate the same sigma given the same (gibberish) m? Or we don't care?

Thanks. 83.67.217.254 06:50, 17 November 2006 (UTC)