Authors
Mihir Bellare, Thomas Ristenpart
Publication date
2006
Conference
Advances in Cryptology–ASIACRYPT 2006: 12th International Conference on the Theory and Application of Cryptology and Information Security, Shanghai, China, December 3-7, 2006. Proceedings 12
Pages
299-314
Publisher
Springer Berlin Heidelberg
Description
We point out that the seemingly strong pseudorandom oracle preserving (PRO-Pr) property of hash function domain-extension transforms defined and implemented by Coron et. al. [1] can actually weaken our guarantees on the hash function, in particular producing a hash function that fails to be even collision-resistant (CR) even though the compression function to which the transform is applied is CR. Not only is this true in general, but we show that all the transforms presented in [1] have this weakness. We suggest that the appropriate goal of a domain extension transform for the next generation of hash functions is to be multi-property preserving, namely that one should have a single transform that is simultaneously at least collision-resistance preserving, pseudorandom function preserving and PRO-Pr. We present an efficient new transform that is proven to be multi-property preserving in this sense.
Total citations
20052006200720082009201020112012201320142015201620172018201920202021202220232024222032322314281164864103331
Scholar articles
M Bellare, T Ristenpart - Advances in Cryptology–ASIACRYPT 2006: 12th …, 2006