Short Digital Signatures and ID- KEMs via Truncation Collision Resistance
Tibor Jager Paderborn University
1
Short Digital Signatures and ID- KEMs via Truncation Collision - - PowerPoint PPT Presentation
Short Digital Signatures and ID- KEMs via Truncation Collision Resistance Tibor Jager Rafael Kurek Paderborn University Paderborn University 1 Contributions New security notion for standard Hash Functions Truncation-Collision
1
2
3
“Cryptographic Hash Function modelled as truly random function”
4
“Cryptographic Hash Function modelled as truly random function”
5
“Cryptographic Hash Function modelled as truly random function”
f
6
Selective Adversary Adaptive Adversary pk
7
M*
Selective Adversary Adaptive Adversary pk
8
M* pk
Selective Adversary Adaptive Adversary pk
9
M* pk 𝑛'
𝜏 '
Selective Adversary Adaptive Adversary pk (m*, 𝜏*)
10
M* pk 𝑛' 𝜏*
𝜏 '
Selective Adversary Adaptive Adversary pk (m*, 𝜏*)
11
M* pk 𝑛' 𝜏*
𝜏 '
Selective Adversary Adaptive Adversary pk (m*, 𝜏*)
12
M* pk 𝑛' 𝜏*
𝜏 '
13
14
15
16
3(3=>) EFGH
17
3(3=>) EFGH
18
19
Easier to guess
20
Easier to guess More collision resistant
21
Easier to guess More collision resistant
Collision Resistant Easy to guess Length j
22
23
H( ? ) 𝐼>(m) 𝐼E(m) 𝐼EJKL M(m) m 𝐼EN(m)
𝐼' Prefix of length i H Tru-CR
24
H( ? ) 𝐼>(m) 𝐼E(m) 𝐼EJKL M(m) Sig(𝑡𝑙>, ? )
𝜏 = (𝜏 >,..,𝜏 PQR %)
m 𝐼EN(m) Sig(𝑡𝑙S, ? ) Sig(𝑡𝑙E, ? ) Sig(𝑡𝑙PQR %, ? )
𝐼' Prefix of length i H Tru-CR Sig selective secure
25
Selective Adversary Adaptive Adversary
26
Breaking weak scheme with message length j
Selective Adversary Adaptive Adversary pk*
27
pk=(𝑞𝑙S,..., pk*,…)
M* ← 0,1 T M* (𝑞𝑙', 𝑡𝑙') ← 𝐿𝑓𝑧𝐻𝑓𝑜
Selective Adversary Adaptive Adversary pk*
28
pk=(𝑞𝑙S,..., pk*,…) m 𝜏 = (𝜏 S, … , 𝜏
T, . . . )
M* ← 0,1 T 𝜏 ' = Sig(𝑡𝑙' , 𝐼EF(m)) 𝐼
T(m)
𝜏 T
M* (𝑞𝑙', 𝑡𝑙') ← 𝐿𝑓𝑧𝐻𝑓𝑜
Selective Adversary Adaptive Adversary pk* m*, 𝜏* = (𝜏S
∗, … , 𝜏 T ∗, …)
29
pk=(𝑞𝑙S,..., pk*,…) m 𝜏 = (𝜏 S, … , 𝜏
T, . . . )
𝜏
T ∗
M* ← 0,1 T 𝜏 ' = Sig(𝑡𝑙' , 𝐼EF(m)) 𝐼
T(m)
𝜏 T
M* (𝑞𝑙', 𝑡𝑙') ← 𝐿𝑓𝑧𝐻𝑓𝑜
Selective Adversary Adaptive Adversary pk* m*, 𝜏* = (𝜏S
∗, … , 𝜏 T ∗, …)
30
pk=(𝑞𝑙S,..., pk*,…) m 𝜏 = (𝜏 S, … , 𝜏
T, . . . )
𝜏
T ∗
M* ← 0,1 T 𝜏 ' = Sig(𝑡𝑙' , 𝐼EF(m)) 𝐼
T(m)
𝜏 T
M*
f
T(m*)? ✅
(𝑞𝑙', 𝑡𝑙') ← 𝐿𝑓𝑧𝐻𝑓𝑜
31
1 x0+H1(m)
i=1 1 xi+H2i (m)
<latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="X/BbPQRM1pmBhxdK1enSbL+gJw=">AB2HicbZDNSgMxFIXv1L86Vq1rN8EiuCozbtSd4MZlBcW2qFkMnfa0ExmSO4IpfQFXLhRfDB3vo3pz0KtBwIf5yTk3pOUSloKgi+vtrW9s7tX3/cPGv7h0XGz8WSLygiMRKEK0u4RSU1RiRJYa80yPNEYTeZ3C3y7jMaKwv9SNMS45yPtMyk4OSszrDZCtrBUmwTwjW0YK1h83OQFqLKUZNQ3Np+GJQUz7ghKRTO/UFlseRiwkfYd6h5jaeLcecs3PnpCwrjDua2NL9+WLGc2uneJu5pzG9m+2MP/L+hVl1/FM6rIi1GL1UVYpRgVb7MxSaVCQmjrgwkg3KxNjbrg14zvOgj/brwJ0WX7ph0+BFCHUziDCwjhCm7hHjoQgYAUXuDNG3uv3vuqpq37uwEfsn7+AaqKYoN</latexit><latexit sha1_base64="Uahei4cNx8ueXMo8H4E759/pRL4=">ACPnicbZA/TxsxGMbf40+hKbQpaxerqFIQUnTHAh2QkFgygtQUpFw4+RzfxYp9PtnvISLn4+lExsfgoWBVkw4IQMFXsnS4+fxI9u/vJbCYhzfRkvLK6sf1tY/tj5tbH7+0v68dvqxjDeZ1pqc5Ty6WoeB8FSn5eG05VLvlZPjme5WeX3Fihq184rflQ0bIShWAUg5W1aWpFqSg5JKnkBXbKC5cWhjKXeHeVxWSX9LKko3a8T40ox7gT8troUebEYeLDRuqSTPyLjtjtZW7vwgnv572svR134/mQtyJZiG1YzEnWvklHmjWKV8gktXaQxDUOHTUomOS+lTaW15RNaMkHQVZUcTt0cxSe/AjOiBTahFUhmbsvG4qa6cqDycVxbF9nc3M97JBg8XB0ImqbpBX7PmiopENZlxJSNhOEM5DYIyI8JbCRvTQAUD/VaAkLz+8lvR3+v+7CanMazDN/gOHUhgH46gByfQBwbXcAcP8Df6E91H/5pLULbFvw30SPT51ashU=</latexit><latexit sha1_base64="Uahei4cNx8ueXMo8H4E759/pRL4=">ACPnicbZA/TxsxGMbf40+hKbQpaxerqFIQUnTHAh2QkFgygtQUpFw4+RzfxYp9PtnvISLn4+lExsfgoWBVkw4IQMFXsnS4+fxI9u/vJbCYhzfRkvLK6sf1tY/tj5tbH7+0v68dvqxjDeZ1pqc5Ty6WoeB8FSn5eG05VLvlZPjme5WeX3Fihq184rflQ0bIShWAUg5W1aWpFqSg5JKnkBXbKC5cWhjKXeHeVxWSX9LKko3a8T40ox7gT8troUebEYeLDRuqSTPyLjtjtZW7vwgnv572svR134/mQtyJZiG1YzEnWvklHmjWKV8gktXaQxDUOHTUomOS+lTaW15RNaMkHQVZUcTt0cxSe/AjOiBTahFUhmbsvG4qa6cqDycVxbF9nc3M97JBg8XB0ImqbpBX7PmiopENZlxJSNhOEM5DYIyI8JbCRvTQAUD/VaAkLz+8lvR3+v+7CanMazDN/gOHUhgH46gByfQBwbXcAcP8Df6E91H/5pLULbFvw30SPT51ashU=</latexit><latexit sha1_base64="i4TCMObQOQBHjI4EjsKmFzqn5Ms=">ACSXicbVAxTxsxGPWFmigNCxi9UIKQgpustCGSIhumSkEilIuXDyOb6LFft8sr9DRJZ/HwtTN34EC0NBnXBChpTwJEvP731Pn/3SUnADYXgf1NY+fFzf2PxU39r+vPOlsbv326hKU9anSih9mRLDBC9YHzgIdlqRmQq2EU6+TnzL6ZNlwV5zAt2VCSvOAZpwS8lDRIbHguCe7iWLAMWvmVjTNqI2cvUlCfIh7SdSB87FmudjOPB+qdUosbwbOX8RKscTt5Th73Edq4sd26eSxrNsB3OgVdJtCBNtMBZ0vgTjxStJCuACmLMIApLGFqigVPBXD2uDCsJnZCcDTwtiGRmaOdVOLzvlRHOlPanADxXlxOWSGOmMvWTksDYvPVm4nveoILsx9DyoqyAFfR1UVYJDArPesUjrhkFMfWEUM39WzEdE98K+PbrvoTo7ZdXSb/TPm5Hv8LmyemijU30DX1HLRShI3SCeugM9RFt+gB/UVPwV3wGDwH/15Ha8Ei8xX9h9raC0kLsY=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit><latexit sha1_base64="xuNC0VwgL/c39wSfM8d36VWL+AY=">ACSXicbVDPSyMxGM1Ud9XuD6sevQSLUBHKTBF0D4K4lx4VrAqdOmTSzDQ0mQzJN7Il5O/z4snb/hFePLiLJ9Pag78eBF7e+x5f8tJScANh+DeoLSx+bq0vFL/9v3Hz9XG2vq5UZWmrEeVUPoyJYJXrAecBDstSMyFSwi3T8e+pfXDNtuCrOYFKygSR5wTNOCXgpaZDY8FwSfIhjwTJo5Vc2zjShNnL2TxLiXdxNopbcS7WPB/BjvdLrYaJ5YeR8xehcjx2rzJ8t5vYzpXlzs1ySaMZtsMZ8EcSzUkTzXGSNO7ioaKVZAVQYzpR2EJA0s0cCqYq8eVYSWhY5KzvqcFkcwM7KwKh7e9MsSZ0v4UgGfq64Ql0piJTP2kJDAy72p+JnXryA7GFhelBWwgr4syiqBQeFpr3jINaMgJp4Qqrl/K6Yj4lsB37dlxC9/JH0u0f7Wj073m0fG8jW0ibZQC0VoHx2hLjpBPUTRDbpHj+hfcBs8BP+Dp5fRWjDPbKA3qC08A0pLso=</latexit>birthday algorithm exists
32
33
34
35
36