Constructing an Ideal Hash Function from Weak Ideal Compression Functions

Constructing an Ideal Hash Function from Weak Ideal Compression Functions
复制标题

DOI:
10.1007/978-3-540-74462-7_25
复制
发表时间:
2006-08
期刊:
--
影响因子:
--
通讯作者:
Moses D. Liskov
Moses D. Liskov
中科院分区:
其他
文献类型:
--
作者:
Moses D. Liskov

文献摘要

被引文献

相似文献

我们引入了弱理想压缩函数的概念,它容易受到强烈形式的攻击,但在其他方面是随机的。我们证明,这种弱理想压缩函数可用于创建安全散列函数,从而提供一种可用于消除由压缩函数的不良特性引起的攻击的设计。我们证明,我们给出的构造(我们称之为“拉链散列”)是理想的,因为当使用这些弱理想构建块实现时,整体散列函数与随机预言没有区别。拉链散列函数相对简单,每个输入块需要两次压缩函数评估,但它不可流式传输。我们还展示了如何从理想的弱压缩函数创建理想的(强)压缩函数,它可以以标准迭代的方式使用来创建可流式哈希函数。
We introduce the notion of aweakideal compression function, which is vulnerable to strong forms of attack, but is otherwise random. We show that such weak ideal compression functions can be used to create secure hash functions, thereby giving a design that can be used to eliminate attacks caused by undesirable properties of compression functions.We prove that the construction we give, which we call the “zipper hash,” isidealin the sense that the overall hash function is indistinguishable from a random oracle when implemented with these weak ideal building blocks.The zipper hash function is relatively simple, requiring two compression function evaluations per block of input, but it is not streamable. We also show how to create an ideal (strong) compression function from ideal weak compression functions, which can be used in the standard iterated way to make a streamable hash function.