Lune

EUROCRYPT2020Top-tier venue

Tight Time-Space Lower Bounds for Finding Multiple Collision Pairs and Their Applications

Itai Dinur

2020Year
16Citations
5Top-tier citations

Abstract

We consider a collision search problem (CSP), where given a parameter CC, the goal is to find CC collision pairs in a random function f:[N]→[N]f:[N] \rightarrow [N] (where [N]={0,1,…,N−1})[N] = \{0,1,\ldots,N-1\}) using SS bits of memory. Algorithms for CSP have numerous cryptanalytic applications such as space-efficient attacks on double and triple encryption. The best known algorithm for CSP is parallel collision search (PCS) published by van Oorschot and Wiener, which achieves the time-space tradeoff T2⋅S=O~(C2⋅N)T^2 \cdot S = \tilde{O}(C^2 \cdot N) for S=O~(C)S = \tilde{O}(C).

In this paper, we prove that any algorithm for CSP satisfies T2⋅S=Ω~(C2⋅N)T^2 \cdot S = \tilde{\Omega}(C^2 \cdot N) for S=O~(C)S = \tilde{O}(C), hence the best known time-space tradeoff is optimal (up to poly-logarithmic factors in NN). On the other hand, we give strong evidence that proving similar unconditional time-space tradeoff lower bounds on CSP applications (such as breaking double and triple encryption) may be very difficult, and would imply a breakthrough in complexity theory. Hence, we propose a new restricted model of computation and prove that under this model, the best known time-space tradeoff attack on double encryption is optimal.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 4a1aca65-c71c-40d3-814f-d5543642a3bd

Cited by top-tier papers5

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines