Cryptography Reference
In-Depth Information
de
=
subset
J
,welet
r
J
⊕
j∈J
s
j
. The reader can easily verify that the
r
J
's
are pairwise independent and each is uniformly distributed in
}
|x|
.
The key observation is that
b
(
x, r
J
)=
b
(
x, ⊕
j∈J
s
j
)=
⊕
j∈J
b
(
x, s
j
).
Hence, our guess for
b
(
x, r
J
)is
{
0
,
1
⊕
j∈J
σ
j
, and with noticeable probabil-
ity all our guesses are correct.