Better Than Advertised: Improved Collision-Resistance Guarantees for MD-Based Hash Functions
Mihir Bellare, Joseph Jaeger, Julia Len
摘要
The MD transform that underlies the MD and SHA families iterates a compression function h to get a hash function H. The question we ask is, what property X of h guarantees collision resistance (CR) of H? The classical answer is that X itself be CR. We show that weaker conditions X, in particular forms of what we call constrained-CR, suffice. This reduces demands on compression functions, to the benefit of security, and also, forensically, explains why collisionfinding attacks on compression functions have not, historically, lead to immediate breaks of the corresponding hash functions. We obtain our results via a definitional framework called RS security, and a parameterized treatment of MD, that also serve to unify prior work and variants of the transform.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
相关 Paper
- Collision-Resistance from Multi-Collision-ResistanceRon D. Rothblum, Prashant Nalini VasudevanCRYPTO 2022 · 被引用 8 次
- Optimal Security for Keyed Hash Functions: Avoiding Time-Space Tradeoffs for Finding CollisionsCody Freitag, Ashrujit Ghoshal, Ilan KomargodskiEUROCRYPT 2023 · 被引用 8 次
- Instance Compression, RevisitedGal Arnon, Shany Ben-David, Eylon YogevEUROCRYPT 2025 · 被引用 2 次
- Collision Resistance from Multi-collision Resistance for All Constant ParametersJan Buzek, Stefano TessaroCRYPTO 2024 · 被引用 3 次
- Random Oracle Combiners: Breaking the Concatenation Barrier for Collision-ResistanceYevgeniy Dodis, Niels Ferguson, Eli Goldin, Peter Hall 等CRYPTO 2023 · 被引用 2 次
