Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Keying Merkle-Damgård at the Suffix

View through CrossRef
A classical way to turn a cryptographic hash function into a MAC (message authentication code) function is by concatenating key and message and interpreting the result as a tag. For the Merkle-Damgård hash function construction, the approach to prepend the key to the message is known to be insecure, as it is vulnerable to the length extension attack. This observation eventually resulted in the introduction of the HMAC construction. The alternative approach to append the key to the message, even though it already dates back to a work of Tsudik from 1992, has never been investigated in detail. In this work, we perform an in-depth treatment on the possibilities to design a MAC function from the Merkle-Damgård hash function construction by processing the key at the suffix. We formalize two constructions: the suffix keyed Merkle-Damgård construction that simply appends key to message, and the suffix blinded Merkle-Damgård construction that blinds the state before compressing the last message, much like the suffix keyed sponge construction (SuKS). We subsequently prove that both constructions are secure in the standard model under reasonable assumptions on the underlying compression function. We finally investigate the security of these constructions in the leaky setting, and demonstrate that the suffix keyed Merkle-Damgård construction is not leakage resilient, but the suffix blinded Merkle-Damgård construction is leakage resilient as long as an appropriate padding rule is adopted and as long as the underlying building blocks are processing secret data in a leakage resilient manner.
Universitatsbibliothek der Ruhr-Universitat Bochum
Title: Keying Merkle-Damgård at the Suffix
Description:
A classical way to turn a cryptographic hash function into a MAC (message authentication code) function is by concatenating key and message and interpreting the result as a tag.
For the Merkle-Damgård hash function construction, the approach to prepend the key to the message is known to be insecure, as it is vulnerable to the length extension attack.
This observation eventually resulted in the introduction of the HMAC construction.
The alternative approach to append the key to the message, even though it already dates back to a work of Tsudik from 1992, has never been investigated in detail.
In this work, we perform an in-depth treatment on the possibilities to design a MAC function from the Merkle-Damgård hash function construction by processing the key at the suffix.
We formalize two constructions: the suffix keyed Merkle-Damgård construction that simply appends key to message, and the suffix blinded Merkle-Damgård construction that blinds the state before compressing the last message, much like the suffix keyed sponge construction (SuKS).
We subsequently prove that both constructions are secure in the standard model under reasonable assumptions on the underlying compression function.
We finally investigate the security of these constructions in the leaky setting, and demonstrate that the suffix keyed Merkle-Damgård construction is not leakage resilient, but the suffix blinded Merkle-Damgård construction is leakage resilient as long as an appropriate padding rule is adopted and as long as the underlying building blocks are processing secret data in a leakage resilient manner.

Related Results

ADJECTIVE SUFFIXES IN THE HATE U GIVE NOVEL: ITS FORMS AND QUANTITIES
ADJECTIVE SUFFIXES IN THE HATE U GIVE NOVEL: ITS FORMS AND QUANTITIES
:  This study aims to classify and describe the types of suffixes used to form adjectives found in novel titled The Hate U Give, determine the meanings indicated by the process as ...
Suffix Tree Data Structures for Matrices
Suffix Tree Data Structures for Matrices
We discuss the suffix tree generalization to matrices in this chapter. We extend the suffix tree notion (described in Chapter 3) from text strings to text matrices whose entries ar...
AFIKSASI DALAM PENINGKATAN VALENSI VERBA BAHASA JAWA DAN BAHASA BANJAR
AFIKSASI DALAM PENINGKATAN VALENSI VERBA BAHASA JAWA DAN BAHASA BANJAR
Abstrak Penelitian ini merupakan penelitian kualitatif yang bertujuan untuk untuk mengetahui proses afiksasi yang berperan terhadap peningkatan valensi verba dalam bahasa Jaw...
Sufiks Pembentuk Verba Transitif Dan Intransitif Dalam Bahasa Jepang
Sufiks Pembentuk Verba Transitif Dan Intransitif Dalam Bahasa Jepang
(Title: Suffix Formers of Transitive And Intransitive Verbs In Japanese Language) This research aims to explain the process of formation verbs from the suffix of transitive and int...
FROM MERKLE–DAMGÅRD TO SPONGE: ARCHITECTURAL IMPACT ON HASH FUNCTION SECURITY
FROM MERKLE–DAMGÅRD TO SPONGE: ARCHITECTURAL IMPACT ON HASH FUNCTION SECURITY
The paper investigates the influence of cryptographic hash function architecture on their cryptographic strength. The main focus is on a comparative analysis of the classical Merkl...
Security of the Suffix Keyed Sponge
Security of the Suffix Keyed Sponge
We formalize and analyze the general suffix keyed sponge construction, a pseudorandom function built on top of a cryptographic permutation. The construction hashes its data using t...
Aspecte ale derivării cu sufixul -iște
Aspecte ale derivării cu sufixul -iște
ASPECTS OF THE DERIVATION WITH THE SUFFIX -IȘTE Abstract In this paper, I aimed to make a very rigorous inventory of derivatives with the suffix -iște from the Romanian language, t...
Functions of Suffix -an in Javanese
Functions of Suffix -an in Javanese
This article aims at describing functions of suffix –an in Javanese. Suffix -an is the most utilised suffix in Javanese, this suffix is used to create nouns, verbs and adjectives i...

Back to Top