Compactness of Hashing Modes and Efficiency Beyond Merkle Tree
Elena Andreeva, Rishiraj Bhattacharyya, Arnab Roy
摘要
We revisit the classical problem of designing optimally efficient cryptographically secure hash functions. Hash functions are traditionally designed via applying modes of operation on primitives with smaller domains. The results of Shrimpton and Stam (ICALP 2008), Rogaway and Steinberger (CRYPTO 2008), and Mennink and Preneel (CRYPTO 2012) show how to achieve optimally efficient designs of 2nto-n-bit compression functions from non-compressing primitives with asymptotically optimal 2-query collision resistance. Designing optimally efficient and secure hash functions for larger domains (> 2n bits) is still an open problem. To enable efficiency analysis and comparison across hash functions built from primitives of different domain sizes, in this work we propose the new compactness efficiency notion. It allows us to focus on asymptotically optimally collision resistant hash function and normalize their parameters based on Stam’s bound from CRYPTO 2008 to obtain maximal efficiency. We then present two tree-based modes of operation as a design principle for compact, large domain, fixed-input-length hash functions. 1. Our first construction is an Augmented Binary Tree (ABR) mode. The design is a (2 + 2 − 1)n-to-n-bit hash function making a total of (2 − 1) calls to 2n-to-n-bit compression functions for any l ≥ 2. Our construction is optimally compact with asymptotically (optimal) 2-query collision resistance in the ideal model. For a tree of height l, in comparison with Merkle tree, the ABR mode processes additional (2−1) data blocks making the same number of internal compression function calls. 2. With our second design we focus our attention on the indifferentiability security notion. While the ABR mode achieves collision resistance, it fails to achieve indifferentiability from a random oracle within 2 queries. ABR compresses only 1 less data block than ABR with the same number of compression calls and achieves in addition indifferentiability up to 2 queries. Both of our designs are closely related to the ubiquitous Merkle Trees and have the potential for real-world applicability where the speed of hashing is of primary interest.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Block-Cipher-Based Tree HashingAldo GunsingCRYPTO 2022 · 被引用 6 次
- The Billion Dollar Merkle TreeThomas Coratger, Dmitry Khovratovich, Bart Mennink, Benedikt WagnerCCS 2026
- Boosting Efficiency and Security in Arithmetization-Oriented Hashing for Zero-Knowledge Proof SystemsElena Andreeva, Rishiraj Bhattacharyya, Arnab Roy, Stefano TrevisaniUSENIX Security 2026
它引用的顶会 Paper1
相关 Paper
- Optimal Security for Keyed Hash Functions: Avoiding Time-Space Tradeoffs for Finding CollisionsCody Freitag, Ashrujit Ghoshal, Ilan KomargodskiEUROCRYPT 2023 · 被引用 8 次
- Random Oracle Combiners: Breaking the Concatenation Barrier for Collision-ResistanceYevgeniy Dodis, Niels Ferguson, Eli Goldin, Peter Hall 等CRYPTO 2023 · 被引用 2 次
- Random Oracle Combiners: Merkle-Damgård StyleYevgeniy Dodis, Eli Goldin, Peter HallEUROCRYPT 2025
- Time-Space Lower Bounds for Finding Collisions in Merkle-Damgård Hash FunctionsAkshima, Siyao Guo, Qipeng LiuCRYPTO 2022 · 被引用 11 次
- Tight Preimage Resistance of the Sponge ConstructionCharlotte Lefevre, Bart MenninkCRYPTO 2022 · 被引用 15 次
