Consider a strengthened version of unforgeability (Definition 4.16) where A is additionally given access to a decryption oracle.
(a) Write a formal definition for this version of unforgeability.
(b) Prove that Construction 4.18 satisfies this stronger definition if ΠM is a strongly secure MAC.
(c) Show by counterexample that Construction 4.18 need not satisfy this stronger definition if ΠM is a secure MAC that is not strongly secure. (Compare to the previous exercise.)