We show that it is impossible to extend the strong BRSIM/UC results to usual Dolev-Yao models of hash functions in the general case. These models treat hash functions as free operators of the term algebra. In contrast, we show that these models are sound in the same strict sense in the random oracle model of cryptography. For the standard model of cryptography, we also discuss several conceivable restrictions to the Dolev-Yao models and classify them into possible and impossible cases.
Category / Keywords: foundations / Dolev-Yao models, symbolic hash functions, simulatability, UC, impossibility Date: received 21 Feb 2006, last revised 1 May 2007 Contact author: backes at cs uni-sb de Available format(s): PDF | BibTeX Citation Note: PDF version added Version: 20070501:170949 (All versions of this report) Short URL: ia.cr/2006/068 Discussion forum: Show discussion | Start new discussion