A Lightweight 256-Bit Hash Function for Hardware and Low-End Devices: Lesamnta-LW

A Lightweight 256-Bit Hash Function for Hardware and Low-End Devices: Lesamnta-LW
复制标题

DOI:
10.1007/978-3-642-24209-0_10
复制
发表时间:
2010-12
期刊:
--
影响因子:
--
通讯作者:
Shoichi Hirose;K. Ideguchi;H. Kuwakado;Toru Owada;B. Preneel;Hirotaka Yoshida
Shoichi Hirose;K. Ideguchi;H. Kuwakado;Toru Owada;B. Preneel;Hirotaka Yoshida
中科院分区:
其他
文献类型:
--
作者:
Shoichi Hirose;K. Ideguchi;H. Kuwakado;Toru Owada;B. Preneel;Hirotaka Yoshida

文献摘要

相似文献

本文提出了一种新的轻量级256位散列函数Lesamnta-LW,其针对碰撞、原像和第二原像攻击的安全级别至少为2120。我们采用Merkle-Damgård域扩展;压缩函数是从使用LW 1模式的专用AES分组密码构造的,可以证明其安全性降低。在轻量级实现方面,Lesamnta-LW相对于其他256位哈希函数具有竞争优势。我们对Lesamnta-LW进行了尺寸优化的硬件实现,在90 nm技术上仅需要8.24 Kgates。我们的Lesamnta-LW软件实现只需要50字节的RAM,并在8位CPU上快速运行短消息。
This paper proposes a new lightweight 256-bit hash function Lesamnta-LW with claimed security levels of at least 2120with respect to collision, preimage, and second preimage attacks. We adopt the Merkle-Damgård domain extension; the compression function is constructed from a dedicated AES-based block cipher using the LW1 mode, for which a security reduction can be proven. In terms of lightweight implementations, Lesamnta-LW offers a competitive advantage over other 256-bit hash functions. Our size-optimized hardware implementation of Lesamnta-LW requires only 8.24 Kgates on 90 nm technology. Our software implementation of Lesamnta-LW requires only 50 bytes of RAM and runs fast on short messages on 8-bit CPUs.