Security of Practical Cryptosystems Using Merkle-Damgård Hash Function in the Ideal Cipher Model

Security of Practical Cryptosystems Using Merkle-Damgård Hash Function in the Ideal Cipher Model
复制标题

DOI:
10.1007/978-3-642-24316-5_20
复制
发表时间:
2011-10
期刊:
--
影响因子:
--
通讯作者:
Yusuke Naito;Kazuki Yoneyama;Lei Wang;K. Ohta
Yusuke Naito;Kazuki Yoneyama;Lei Wang;K. Ohta
中科院分区:
其他
文献类型:
--
作者:
Yusuke Naito;Kazuki Yoneyama;Lei Wang;K. Ohta

文献摘要

相似文献

在本文中,我们阐明了基于密钥导出函数(KDF)的哈希函数的实用密码系统的安全性。我们使用不可微性框架来讨论安全性,因为来自Random Oracle(及其变体)的不可微性保证了密码系统保持安全,即使Random Oracle(RO)使用散列函数实例化。虽然以前的Merkle-Damgård(MD)散列函数的不可微性的工作集中在独立的散列函数,有没有工作集中在MD散列函数与KDF。许多密码系统需要比独立散列函数更长的散列函数输出长度,并且KDF用于生成PKCS #1 v2.1和IEEE P1363中指定的更长的散列。具体来说,我们得到以下结果。我们用MD-SCFIS表示使用Stam的第二类压缩函数的MD散列函数,用KDF-MD-SCFIS表示使用KDF的MD-SCFIS。在pub-RO模型中安全的密码系统(FDH,PSS,Fiat-Shamir等):Dodiset等人提出了pub-RO的不可微性来证明使用MD-SCFIS的这些密码系统的安全性,而没有考虑KDF结构。因此,我们提出了一个不同的框架,从privleak-RO不可区分。RO模型下的加密方案(OAEP,RSA KEM,PSEC-KEM,ECIES-KEM等):在“固定输入长度”RO模型下,加密方案是安全的,因为加密方案的RO的输入长度是固定的。我们表明,这一事实保证了使用KDF-MD-SCFII加密方案的安全性。
In this paper, we clarify the security of practical cryptosystems with hash functions based on key derivation functions (KDFs). We use the indifferentiability framework in order to discuss the security because the indifferentiability from Random Oracle (and its variants) guarantees that cryptosystems remain secure even if Random Oracles (ROs) are instantiated with hash functions. Though previous works on the indifferentiability of Merkle-Damgård (MD) hash functions focus on stand-alone hash functions, there is no work which focuses on MD hash functions with KDFs. Many cryptosystems need longer output lengths of hash functions than stand-alone hash functions and KDFs are used to generate longer digests as specified in PKCS #1 v2.1 and IEEE P1363. Specifically, we obtain the following results. We denote the MD hash function using Stam’s type-II compression function by MD-SCFII and MD-SCFII with KDFs by KDF-MD-SCFII.Cryptosystems secure in the pub-RO model (FDH, PSS, Fiat-Shamir, and so on): Dodiset al.proposed the indifferentiability from pub-RO to prove the security of these cryptosystems using MD-SCFII while did not consider the KDF structures. So we propose a different framework, indifferentiability from privleak-RO. Using this framework and their result, we show that these cryptosystems using KDF-MD-SCFIIs are secure.Encryption schemes secure in the RO model (OAEP, RSA-KEM, PSEC-KEM, ECIES-KEM and so on): The encryption schemes are secure in the “fixed inputl length” RO model because the input lengths of ROs from the encryption schemes are fixed. We show that this fact guarantees the security of the encryption schemes using KDF-MD-SCFII.