Paper 2012/597
A Novel Permutation-based Hash Mode of Operation FP and the Hash Function SAMOSA
Souradyuti Paul, Ekawat Homsirikamol, and Kris Gaj
Abstract
The contribution of the paper is two-fold. First, we design a novel permutation-based hash mode of operation FP, and analyze its security. The FP mode is derived by replacing the hard-to-invert primitive of the FWP mode -- designed by Nandi and Paul, Indocrypt 2010 -- with an easy-to-invert permutation; since easy-to-invert permutations with good cryptographic properties are normally easier to design, and are more efficient than the hard-to-invert functions, the FP mode is more suitable in practical applications than the FWP mode.
We show that any n-bit hash function that uses the FP mode is indifferentiable from a random oracle up to 2^n/2 queries (up to a constant factor), if the underlying 2n-bit permutation is free from any structural weaknesses. Based on our further analysis and experiments, we conjecture that the FP mode is resistant to all non-trivial generic attacks with work less than the brute force, mainly due to its large internal state. We compare the FP mode with other permutation-based hash modes, and observe that it displays the so-far best security/rate trade-off.
To put this into perspective, our second contribution is a proposal for a concrete hash function SAMOSA using the new mode and the
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published elsewhere. Indocrypt 2012
- Keywords
- Hash modeindifferentiabilitypermutationFPGA implementation
- Contact author(s)
- souradyuti paul @ gmail com
- History
- 2012-10-25: received
- Short URL
- https://ia.cr/2012/597
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2012/597, author = {Souradyuti Paul and Ekawat Homsirikamol and Kris Gaj}, title = {A Novel Permutation-based Hash Mode of Operation {FP} and the Hash Function {SAMOSA}}, howpublished = {Cryptology {ePrint} Archive, Paper 2012/597}, year = {2012}, url = {https://eprint.iacr.org/2012/597} }