0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
Weak-Key Classes and Key Recovery in Key-Then-Hash Functions
- 1.Handschuh-Preneel의 약한 키 클래스 개념을 Key-Then-Hash(KTH) 형식화로 통합 분석
- 2.KTH 오프셋 불변성을 통해 공격 성공 확률이 특정 절대 키값과 무관함을 증명
- 3.3라운드 Xoodoo 기반 Serial 구성에 Wegman-Carter-Shoup 키복구 공격을 성공, 384비트 키 전체 복구
- 4.약 2^42회 시행(약 2^43회 MAC 오라클 호출)으로 공격 실행, 대상은 3라운드 Xoodoo로 한정
왜 중요한가?
실용 MAC 구성인 Wegman-Carter-Shoup 방식이 축약 라운드 Xoodoo와 결합될 때 실제로 완전한 키 복구가 가능함을 실증해, 해시 기반 인증 프로토콜 설계에서 라운드 수 축소의 위험성을 구체적 공격 비용으로 보여준다.
본문 미리보기
Handschuh and Preneel define a weak-key class by “unexpected” security behavior and efficient detection of class membership. Four families in their CRYPTO 2008 analysis, NH, NMH, WH, and Square Hash, fall within the later key-then-hash (KTH) formalism. For the controlled collision and fixed-difference attacks considered here, KTH offset-invariance shows that any nonempty solution set can be translated to contain any chosen absolute key while preserving its size, success probability, and the numb
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안



