Hash Functions from Defective Ideal Ciphers
Hash Functions from Defective Ideal Ciphers
复制标题
DOI:
10.1007/978-3-319-16715-2_15
复制
发表时间:
2015-04
期刊:
影响因子:
--
通讯作者:
Jonathan Katz;S. Lucks;Aishwarya Thiruvengadam
中科院分区:
文献类型:
--
作者:
Jonathan Katz;S. Lucks;Aishwarya Thiruvengadam
Cryptographic constructions are often designed and analyzed in idealized frameworks such as the random-oracle or ideal-cipher models. When the underlying primitives are instantiated in the real world, however, they may be far from ideal. Constructions should therefore berobustto known or potential defects in the lower-level primitives.With this in mind, we study the construction of collision-resistant hash functions from “defective” ideal ciphers. We introduce a model for ideal ciphers that are vulnerable to differentialrelated-key attacks, and explore the security of the classical PGV constructions from such weakened ciphers. We find that althoughnoneof the PGV compression functions are collision-resistant in our model, it is possible to prove collision resistance up to the birthday bound for iterated (Merkle-Damgård) versions of four of the PGV constructions. These four resulting hash functions are also optimally preimage-resistant.