首页> 外文会议>International conference on information systems security >New HMAC Message Patches: Secret Patch and CrOw Patch
【24h】

New HMAC Message Patches: Secret Patch and CrOw Patch

机译:新的HMAC消息补丁:秘密补丁和CrOw补丁

获取原文

摘要

At Asiacrypt 2012, Peyrin et al. showed generic attacks against the HMAC design. They utilized a pair of related keys where only the relation between the keys is known to the attacker but not the keys themselves (the secret key model). On similar lines, at Crypto 2012, Dodis et al showed differentiability attacks based on ambiguous and colliding keys on HMAC in known/chosen key model. Peyrin et al. also proposed a patching scheme for HMAC and claimed that the proposed patch thwarts their attacks. In this work, we first show that the patch proposed by Peyrin et al. will not prevent their attacks for the HMAC construction for certain "good" cryptographic hash functions. Specifically, we show that no public and reversible patch will prevent their attack on HMAC instantiated with a weakly collision resistant hash function. Following this, we propose two different patches, called the secret patch and the collision resistant one way (CrOw) patch, to thwart the attacks of Peyrin et al. and Dodis et al. Our work is theoretical in nature, and does not threaten the security of HMAC used with standard hash functions. Further, both our patches are designed to be used as wrappers and do not affect the underlying HMAC construction. This property is similar to Peyrin et al.'s patch.
机译:在Asiacrypt 2012上,Peyrin等人。展示了针对HMAC设计的一般攻击。他们利用了一对相关的密钥,其中攻击者只知道密钥之间的关系,而不知道密钥本身(秘密密钥模型)。同样,在Crypto 2012上,Dodis等人展示了基于已知/选择密钥模型中HMAC上模棱两可和冲突的密钥的可区分性攻击。 Peyrin等。还提出了针对HMAC的补丁方案,并声称所提议的补丁阻止了他们的攻击。在这项工作中,我们首先显示Peyrin等人提出的补丁。将不会阻止他们针对某些“良好”加密哈希函数的HMAC构造的攻击。具体来说,我们表明,没有任何公共的和可逆的补丁程序可以阻止它们对以弱碰撞抗性哈希函数实例化的HMAC的攻击。在此之后,我们提出了两种不同的补丁,分别称为秘密补丁和抗碰撞单向(CrOw)补丁,以阻止Peyrin等人的攻击。和Dodis等。我们的工作本质上是理论上的,并不威胁与标准哈希函数一起使用的HMAC的安全性。此外,我们的两个补丁都旨在用作包装器,并且不会影响基础的HMAC构造。此属性类似于Peyrin等人的补丁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号