What output size resists collisions in a xor of independent expansions?

نویسنده

  • D. J. Bernstein
چکیده

Bellare and Micciancio proposed compressing m1, m2, . . . to f1(m1) ⊕ f2(m2) ⊕ . . .. Collisions are easy to find for long messages but are much more difficult to find for short messages. Exactly how secure is the 4-xor compression function (m1, m2, m3, m4) 7→ f1(m1) ⊕ f2(m2) ⊕ f3(m3) ⊕ f4(m4), with an output size of 4b bits? This paper analyzes, under constraints on machine cost and computation time, the chance of finding 4b-bit collisions using an improved version of Wagner’s generalized-birthday algorithm. In particular, as the machine cost grows past 2, the price-performance ratio of this paper’s attack drops below 2, eventually reaching a limit of 2. This paper also proposes the Rumba20 compression function, reusing large components of the Salsa20 stream cipher as a specific choice of functions f1, f2, f3, f4.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A novel design for all-optical NAND/NOR/XOR gates based on nonlinear directional coupler

In this paper a novel all-optical logic NAND, NOR and XOR gate based on nonlinear directional coupler theory is demonstrated. We use the identical structure which contains three waveguides, for designing these gates; the only difference however, is the power of inputs light beam. In other words, while a beam with 4 W/μm in power considered as logical one, the output is NAND gate and if a beam w...

متن کامل

A novel design for all-optical NAND/NOR/XOR gates based on nonlinear directional coupler

In this paper a novel all-optical logic NAND, NOR and XOR gate based on nonlinear directional coupler theory is demonstrated. We use the identical structure which contains three waveguides, for designing these gates; the only difference however, is the power of inputs light beam. In other words, while a beam with 4 W/μm in power considered as logical one, the output is NAND gate and if a beam w...

متن کامل

تحلیل و آزمون عدم تقارن در رفتار سیاستگذاری پولی بانک مرکزی

According to Taylor (1993) rule, the monetary authority responds to deviations of output and of inflation from their targets through nominal interest rate fluctuations regarded as policy instrument. Another specification that has received considerable attention is that policymakers may have asymmetric preferences with regard to their objectives during recessions and expansions. Since according ...

متن کامل

Propose, Analysis and Simulation of an All Optical Full Adder Based on Plasmonic Waves using Metal-Insulator-Metal Waveguide Structure

This paper proposes a full adder with minimum power consumption and lowloss with a central frequency of 1550nm using plasmonic Metal-Insulator-Metal (MIM)waveguide structure and rectangular cavity resonator. This full adder operates based onXOR and AND logic gates. In this full adder, the resonant wave composition of the firstand second modes has been used and we have ob...

متن کامل

Modeling Multiple–Vehicle Property Damage Collisions in Urban Signalized Intersections

Development of disaggregate models for estimating different property damage collision type frequencies in urban intersections has rarely been studied, particularly in Iran. It seems very little research work being implemented for studying the effect factors on collision type frequency at intersections. The main objective of this paper is to develop suitable statistical models to predict types o...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007