Constructing an Ideal Hash Function from Weak Ideal Compression Functions
Constructing an Ideal Hash Function from Weak Ideal Compression Functions
复制标题
DOI:
10.1007/978-3-540-74462-7_25
复制
发表时间:
2006-08
期刊:
影响因子:
--
通讯作者:
Moses D. Liskov
中科院分区:
文献类型:
--
作者:
Moses D. Liskov
We introduce the notion of aweakideal compression function, which is vulnerable to strong forms of attack, but is otherwise random. We show that such weak ideal compression functions can be used to create secure hash functions, thereby giving a design that can be used to eliminate attacks caused by undesirable properties of compression functions.We prove that the construction we give, which we call the “zipper hash,” isidealin the sense that the overall hash function is indistinguishable from a random oracle when implemented with these weak ideal building blocks.The zipper hash function is relatively simple, requiring two compression function evaluations per block of input, but it is not streamable. We also show how to create an ideal (strong) compression function from ideal weak compression functions, which can be used in the standard iterated way to make a streamable hash function.