NI[f] construction
Now: assume f is a MAC
NI[f](k1 k2, x)
k1
f
f
f
?|x|?
f
. . .
IV
? HMAC with keyed compression function f as its building block
unforgeability
VIL-MAC NI[f]
FIL-MAC f
unforgeability
Our theorem
x1
. . .
x2
xn
k1
k1
k2
k1 , k2 secret
x=x1…xn
