2005 | OriginalPaper | Chapter
How to Construct Universal One-Way Hash Functions of Order r
Authors : Deukjo Hong, Jaechul Sung, Seokhie Hong, Sangjin Lee
Published in: Progress in Cryptology - INDOCRYPT 2005
Publisher: Springer Berlin Heidelberg
Activate our intelligent search to find suitable subject content or patents.
Select sections of text to find matching patents with Artificial Intelligence. powered by
Select sections of text to find additional relevant content using AI-assisted search. powered by
At ASIACRYPT 2004, Hong et al. introduced the notion of UOWHFs of order
r
> 0. A UOWHF has the order
r
if it is infeasible for any adversary to win the game for UOWHF where the adversary is allowed
r
adaptive queries to the hash function oracle before outputting his target message. They showed that if a UOWHF has the order
r
, its some-round MD (Merkle-Damgård) or some-level TR (TRee) extension is a UOWHF. Since MD and TR extensions do not require additional key values except the key of compression functions for hashing, their result means that the order of UOWHFs can be useful for minimizing the total key length. In this paper we study how to construct such UOWHFs of order
r
. As the first step, we observe Bellare-Rogaway UOWHF and Naor-Yung UOWHF. It is shown that Bellare-Rogaway UOWHF has the order 0 and that Naor-Yung UOWHF has the order 1. We generalize the construction of Naor-Yung UOWHF based on a one-way permutation to that of the UOWHF of order
r
.