首页> 外文会议>Australasian Conference on Information Security and Privacy(ACISP 2007); 20070702-04; Townsville(AU) >'Sandwich' Is Indeed Secure: How to Authenticate a Message with Just One Hashing
【24h】

'Sandwich' Is Indeed Secure: How to Authenticate a Message with Just One Hashing

机译:“三明治”确实是安全的:如何仅通过一次哈希验证邮件

获取原文
获取原文并翻译 | 示例

摘要

This paper shows that the classical "Sandwich" method, which prepends and appends a key to a message and then hashes the data using Merkle-Damgard iteration, does indeed provide a secure Message Authentication Code (MAC). The Sandwich construction offers a single-key MAC which can use the existing Merkle-Damgard implementation of hash functions as is, without direct access to the compression function. Hence the Sandwich approach gives us an alternative for HMAC particularly in a situation where message size is small and high performance is required, because the Sandwich scheme is more efficient than HMAC: it consumes only two blocks of "waste" rather than three as in HMAC, and it calls the hash function only once, whereas HMAC requires two invocations of hash function. The security result of the Sandwich method is similar to that of HMAC; namely, we prove that the Sandwich construction yields a PRF(Pseudo-Random Functions)-based MAC, provided that the underlying compression function satisfies PRF properties. In theory, the security reduction of the Sandwich scheme is roughly equivalent to that of HMAC, but in practice the requirements on the underlying compression function look quite different. Also, the security of the Sandwich construction heavily relies on the filling and padding methods to the data, and we show several ways of optimizing them without losing a formal proof of security.
机译:本文表明,经典的“三明治”方法确实在提供安全的消息身份验证代码(MAC)的同时,将消息的键添加到密钥中,然后使用Merkle-Damgard迭代对数据进行哈希处理。 Sandwich构造提供了一个单键MAC,可以直接使用哈希函数的现有Merkle-Damgard实现,而无需直接访问压缩函数。因此,Sandwich方法为我们提供了HMAC的替代方案,特别是在消息大小较小且需要高性能的情况下,因为Sandwich方案比HMAC更有效:它仅消耗两个“浪费”块,而不是HMAC中的三个块,并且它仅调用一次哈希函数,而HMAC需要两次调用哈希函数。三明治方法的安全性结果与HMAC相似。即,只要基础压缩函数满足PRF属性,我们证明Sandwich构造会产生基于PRF(伪随机函数)的MAC。从理论上讲,Sandwich方案的安全性降低与HMAC大致相同,但是在实践中,对底层压缩函数的要求看起来完全不同。同样,Sandwich结构的安全性在很大程度上依赖于数据的填充和填充方法,我们展示了几种在不损失正式安全性证据的情况下优化数据的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号