from    
to    
search  

 


清华大学材料科学与工程研究院《材料科学论坛》:Design and Properties of Hybrid...
清华大学材料科学与工程研究院《材料科学论坛》:Photoalignment for liquid crystals
Pseudo-criticality and its implication for the lost conformality
Implications of superadditive algebras in large N field theories for holography
报告题目:
New Generic attacks on Hash-based MACs
 报告人:
Dr. Gaëtan Leurent
Université Catholique de Louvain, Belgique
报告时间:
2013-09-02 10:15
报告地点:
Conference Hall 322, Science Building, Tsinghua University
主办单位:
高等研究院
  简介:
In this talk we study the security of hash-based MAC algorithms
(such as HMAC and NMAC) above the birthday bound. Up to the
 birthday bound, HMAC and NMAC are proven to be secure under
 reasonable assumptions on the hash function.  On the other hand, if
 an n-bit MAC is built from a hash function with a l-bit state
 (l > n), there is a well-known existential forgery attack with
 complexity 2^l/2.  However, the remaining security after
 2^l/2 computations is not well understood.  In particular it is
 widely assumed that if the underlying hash function is sound,
 then a generic universal forgery attack should still require 2^n
 computations and some distinguishing (e.g. distinguishing-H
 but not distinguishing-R) and state-recovery attacks should still
 require 2^l computations.

 In this work, we show that above the birthday bound, hash-based MACs
 offer significantly less security than previously believed.  Our
 main result is a generic distinguishing-H and state-recovery attack
 against hash-based MACs with a complexity of only 2^l/2.  In
 addition, we show a key-recovery attack with complexity 2^3l/4
 against HMAC used with a hash functions with an internal checksum, such as GOST.
 This surprising result shows that the use of a checksum might actually
 weaken a hash function when used in a MAC.

今日相关信息
Improving Counter-cryptanalysis
History of Systems Control (1959-2013...
 
同类别相关信息
公共卫生系列讲座——鼠疫:传染病防控的...
公共卫生系列讲座:面向2030—中国儿童...
清华大学柔性电子技术研究中心3月学术沙...
公共卫生系列讲座:常见精神障碍的遗传易...
公共卫生系列讲座:生物多样性保护及生态...
学术活动