Abstract
At CRYPTO 2008 Stam [7] made the following conjecture: if an m + s-bit to s-bit compression function F makes r calls to a primitive f of n-bit input, then a collision for F can be obtained (with high probability) using r2 (nr - m)/(r + 1) queries to f. For example, a 2n-bit to n-bit compression function making two calls to a random function of n-bit input cannot have collision security exceeding 2n/3. We prove this conjecture up to a constant multiplicative factor and under the condition m′ : = (2m - n(r - 1))/(r + 1) ≥ log2(17). This covers nearly all cases r = 1 of the conjecture and the aforementioned example of a 2n-bit to n-bit compression function making two calls to a primitive of n-bit input. © 2010 Springer-Verlag.
Cite
CITATION STYLE
Steinberger, J. (2010). Stam’s collision resistance conjecture. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6110 LNCS, pp. 597–615). Springer Verlag. https://doi.org/10.1007/978-3-642-13190-5_30
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.