Hash Functions from Defective Ideal Ciphers

Hash Functions from Defective Ideal Ciphers
复制标题

DOI:
10.1007/978-3-319-16715-2_15
复制
发表时间:
2015-04
期刊:
--
影响因子:
--
通讯作者:
Jonathan Katz;S. Lucks;Aishwarya Thiruvengadam
Jonathan Katz;S. Lucks;Aishwarya Thiruvengadam
中科院分区:
其他
文献类型:
--
作者:
Jonathan Katz;S. Lucks;Aishwarya Thiruvengadam

文献摘要

被引文献

相似文献

密码结构通常在理想化的框架中设计和分析,例如随机预言或理想密码模型。然而,当底层原语在真实的世界中被实例化时,它们可能远非理想。因此,构造应该berobustto已知的或潜在的缺陷,在较低的水平primitives.With记住这一点,我们研究了抗碰撞哈希函数的建设从“缺陷”的理想密码。我们介绍了一个模型的理想密码,是脆弱的差分相关密钥攻击,并探讨了经典PGV结构的安全性,从这样的削弱密码。我们发现,虽然在我们的模型中没有PGV压缩函数是抗碰撞的,但对于四个PGV结构的迭代(Merkle-Damgård)版本,证明抗碰撞性达到生日界限是可能的。这四个产生的哈希函数也是最佳的原像抵抗。
Cryptographic constructions are often designed and analyzed in idealized frameworks such as the random-oracle or ideal-cipher models. When the underlying primitives are instantiated in the real world, however, they may be far from ideal. Constructions should therefore berobustto known or potential defects in the lower-level primitives.With this in mind, we study the construction of collision-resistant hash functions from “defective” ideal ciphers. We introduce a model for ideal ciphers that are vulnerable to differentialrelated-key attacks, and explore the security of the classical PGV constructions from such weakened ciphers. We find that althoughnoneof the PGV compression functions are collision-resistant in our model, it is possible to prove collision resistance up to the birthday bound for iterated (Merkle-Damgård) versions of four of the PGV constructions. These four resulting hash functions are also optimally preimage-resistant.