Better Than Advertised: Improved Collision-Resistance Guarantees for MD-Based Hash Functions

Better Than Advertised: Improved Collision-Resistance Guarantees for MD-Based Hash Functions
复制标题

比宣传的更好:改进基于 MD 的哈希函数的抗碰撞保证

DOI:
10.1145/3133956.3134087
复制
发表时间:
2017
期刊:
CCS '17 Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Len, Julia
Len, Julia
中科院分区:
--
文献类型:
--
作者:
Bellare, Mihir;Jaeger, Joseph;Len, Julia

文献摘要

参考文献

被引文献

相似文献

作为MD和SHA家族基础的MD变换迭代压缩函数h以得到散列函数H。我们要问的问题是,h的什么性质X保证了H的抗碰撞性(CR)?经典的答案是X本身就是CR。我们表明,较弱的条件X,我们称之为约束CR的特定形式,就足够了。这减少了对压缩函数的需求,有利于安全性,并且在法医学上也解释了为什么对压缩函数的冲突查找攻击在历史上不会导致相应的哈希函数立即中断。我们得到我们的结果通过一个定义框架称为RS安全,和MD的参数化处理,也有助于统一以前的工作和变换的变体。
The MD transform that underlies the MD and SHA families iterates a compression functionhto get a hash functionH. The question we ask is, what property X ofhguarantees collision resistance (CR) ofH? The classical answer is that X itself be CR. We show that weaker conditions X, in particular forms of what we call constrained-CR, suffice. This reduces demands on compression functions, to the benefit of security, and also, forensically, explains why collision-finding attacks on compression functions have not, historically, lead to immediate breaks of the corresponding hash functions. We obtain our results via a definitional framework called RS security, and a parameterized treatment of MD, that also serve to unify prior work and variants of the transform.
内存紧张的减少
DOI: --
发表时间: 2017
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
Benedikt Auerbach;David Cash;Manuel Fersch;Eike Kiltz
通讯作者: Eike Kiltz
DOI: --
发表时间: 2004
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
G. Laccetti;G. Schmid
通讯作者: G. Schmid