Does Provable Security Exist?
This talk (based on recent joint work with Alfred
Menezes) will start with an introduction to
the notion of ``provable security'' in
public-key cryptography. I will
then analyze some of the results in this area
and explain why I think one should be
a little skeptical.