*Ideal*when and only when:

1. For each key value block cipher is random permutation, a

*'lookup table'*of

*2*elements of

^{n}*n*bits each.

2. Different permutations for the different key values should be chosen independently.

3. It consists of all possible 'lookup tables', thus is no longer random.

## No comments:

## Post a Comment