Abstract
In this paper, we introduce new compression function design principles supporting variable output lengths (multiples of size n). They are based on a function or block cipher with an n-bit output size. In the case of the compression function with a (t + 1)n-bit output size, in the random oracle and ideal cipher models, their maximum advantages from 2 2 the perspective of collision resistance are 0(t2q/2tn + q2/2 (t+1)n). In the case of t = 1, the advantage is near-optimal. In the case of t > 1, the advantage is optimal.
Original language | English |
---|---|
Pages (from-to) | 2607-2614 |
Number of pages | 8 |
Journal | IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences |
Volume | E91-A |
Issue number | 9 |
DOIs | |
State | Published - Sep 2008 |
Keywords
- Hash function
- Ideal cipher model
- Random oracle