Security/Efficiency Tradeoffs for Permutation-Based Hashing
Security/Efficiency Tradeoffs for Permutation-Based Hashing
复制标题
基于排列的哈希的安全性/效率权衡
DOI:
--
复制
发表时间:
2008
期刊:
影响因子:
--
通讯作者:
J. Steinberger
中科院分区:
文献类型:
--
作者:
P. Rogaway;J. Steinberger
We provide attacks and analysis that capture a tradeoff, in the ideal-permutation model, between the speed of a permutation-based hash function and its potential security. We show that any 2n-bit to n-bit compression function will have unacceptable collision resistance it makes fewer than three n-bit permutation invocations, and any 3n-bit to 2n-bit compression function will have unacceptable security if it makes fewer than five n-bit permutation invocations. Any rate-a hash function built from n-bit permutations can be broken, in the sense of finding preimages as well as collisions, in about N1-α queries, where N = 2n. Our results provide guidance when trying to design or analyze a permutation-based hash function about the limits of what can possibly be done.