...
首页> 外文期刊>電子情報通信学会技術研究報告. 情報セキュリティ. Information Security >Weak collision-resistance for variable input length can imply collision-resistance for fixed input length
【24h】

Weak collision-resistance for variable input length can imply collision-resistance for fixed input length

机译:可变输入长度的弱碰撞电阻可以暗示固定输入长度的碰撞电阻

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

HMAC and NMAC are well-known message authentication functions based on cryptographic hash functions such as SHA. HMAC is a modified practical version of NMAC and has not been given any provable security. On the other hand, NMAC is shown to be a message authentication code if its compression function with fixed input length is a message authentication code and its iterated hash function with variable input length constructed with the compression function is weak collision-resistant. In this article, two results are shown on the strength of weak collision-resistance of the iterated hash function in NMAC. First, it is shown that weak collision-resistance of the iterated hash function in NMAC is not implied by pseudorandomness of its compression function even if the MD-strengthening is assumed. Second, weak collision-resistance of the iterated hash function in NMAC implies collision-resistance of its compression function if the compression function is pseudorandom.
机译:HMAC和NMAC是基于SHA等加密散列函数的众所周知的消息认证功能。 HMAC是一种修改的实用版本的NMAC,并未得到任何可提供的安全性。 另一方面,如果具有固定输入长度的压缩功能是消息认证码,并且其具有压缩功能构造的可变输入长度的迭代散列函数是弱的碰撞碰撞函数,则NMAC被示出为消息认证码。 在本文中,在NMAC中迭代哈希函数的弱碰撞抗性强度显示出两种结果。 首先,表明,即使假设MD强化,它的压缩功能的伪随机性也不暗示NMAC中迭代哈希函数的弱碰撞抗性。 其次,如果压缩函数是伪随机,则NMAC中迭代哈希函数的弱碰撞电阻暗示其压缩功能的碰撞电阻。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号