首页> 外文会议>International conference on information systems security >New HMAC Message Patches: Secret Patch and CrOw Patch
【24h】

New HMAC Message Patches: Secret Patch and CrOw Patch

机译:新的HMAC消息补丁:秘密补丁和乌鸦补丁

获取原文

摘要

At Asiacrypt 2012, Peyrin et al. showed generic attacks against the HMAC design. They utilized a pair of related keys where only the relation between the keys is known to the attacker but not the keys themselves (the secret key model). On similar lines, at Crypto 2012, Dodis et al showed differentiability attacks based on ambiguous and colliding keys on HMAC in known/chosen key model. Peyrin et al. also proposed a patching scheme for HMAC and claimed that the proposed patch thwarts their attacks. In this work, we first show that the patch proposed by Peyrin et al. will not prevent their attacks for the HMAC construction for certain "good" cryptographic hash functions. Specifically, we show that no public and reversible patch will prevent their attack on HMAC instantiated with a weakly collision resistant hash function. Following this, we propose two different patches, called the secret patch and the collision resistant one way (CrOw) patch, to thwart the attacks of Peyrin et al. and Dodis et al. Our work is theoretical in nature, and does not threaten the security of HMAC used with standard hash functions. Further, both our patches are designed to be used as wrappers and do not affect the underlying HMAC construction. This property is similar to Peyrin et al.'s patch.
机译:在亚洲2012年,佩丁等人。表现出对HMAC设计的通用攻击。它们利用了一对相关键,其中攻击者只知道键之间的关系,但不是键本身(秘密密钥模型)。在类似的线路上,在Crypto 2012,Dodis等人显示了基于HMAC上的模糊和碰撞键在已知/选择的关键模型中的抗微分攻击。 Peyrin等人。还提出了HMAC的修补方案,并声称建议的补丁阻止了他们的攻击。在这项工作中,我们首先表现出佩丁等人提出的补丁。不会阻止他们对HMAC建设的攻击,以了解某些“好”加密散列函数。具体来说,我们表明,没有公共和可逆的补丁将阻止他们对弱碰撞抗哈希函数的HMAC攻击。在此之后,我们提出了两种不同的贴片,称为秘密补丁和抗冲击的一种方式(乌鸦)贴片,挫败佩丁等人的攻击。和dodis等人。我们的作品是理论上的,并不威胁到标准哈希函数的HMAC的安全性。此外,我们的贴片都设计为用作包装器,不会影响潜在的HMAC结构。此属性类似于Peylin等人。的补丁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号