Method and device for enhancing attack of antigen image and second original image of hash function of sponge structure

By introducing a feedforward mechanism into the hash function of the sponge structure, the transformation function is improved, and the problem of insufficient trade-off between security and efficiency in the existing technology is solved, the security of antigenic and second proto-image attacks is improved, and the more efficient balance of security and efficiency is achieved, and the practical value of hash function in applications such as message authentication, random number generation and data signature is enhanced.

CN120602067APending Publication Date: 2025-09-05UNIV OF CHINESE ACAD OF SCI
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510634695.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing hash function based on sponge structures has shortcomings in terms of safety and efficiency trade-offs, especially in terms of antigenic and second protozoa attacks.

Method used

The feedforward mechanism is used to improve the transformation function in the sponge structure. By introducing a feedforward mechanism in the absorption and extrusion stages, the output summary length is increased and the safety is improved without affecting the calculation efficiency.

Benefits of technology

Without increasing the computational complexity, the security of antigenic image attacks and second proto-image attacks is significantly improved, and the better balance of security and efficiency is achieved, and the practical value of hash function in application scenarios such as message authentication, random number generation and data signatures is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602067A_ABST
    Figure CN120602067A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of cryptography, and relates to a method and a device for enhancing attack of a sponge structure hash function antigen image and a second original image. According to the method, the feedforward mechanism is introduced into the transformation function, the limitation of a traditional sponge structure hash function on safety and calculation efficiency is broken through, and better safety and efficiency balance is achieved. Under the condition that the calculation complexity is not increased, the security of the antigen image attack and the second original image attack can be effectively improved, so that the practical value of the hash function in application scenes such as message authentication, random number generation and data signature is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cryptography technology, and specifically relates to a new sponge structure hash function design method and device, which can improve the security of the hash function against pre-image and second pre-image attacks. Background Art

[0002] Hash functions are widely used in real-world scenarios such as message authentication codes, random number generators, and data signatures. Among them, the design of hash functions based on sponge structures is one of the most popular research directions.

[0003] Based on the transformation function (in Represents a binary string of b bits in length) and a sponge structure constructed by the message padding algorithm Pad like Figure 1 First, use the message filling algorithm to fill the message msg into a bit string M=m0||m1||…||m whose bit length is a multiple of r. k-1 , where m i represents the i-th message block, || represents the concatenation of message blocks, and k represents the number of message blocks. The message padding algorithm Pad depends only on the length of the padded message and r, and is independent of the specific content of the padded message. Therefore, for two messages msg and msg′ of the same length, Pad(msg) = Pad(msg′). The process of processing the padded message M can be divided into two stages, namely the absorption stage and the squeeze stage. In the absorption stage, k r-bit data packets are continuously XORed into the r bits of the internal state, and r is called the absorption bit rate. In the squeeze stage, the output is continuously The r′ bits of the internal state are repeatedly applied, and finally z0||z1||…||z l-1 The final output is obtained after truncating according to the preset output length, and r′ is called the output bit rate. l-1 Indicates the output summary, z i represents the i-th output summary block, l represents the number of output summary blocks. When r=r′, Abbreviated as For the internal state of the SPONGE structure Use outer r (state) represents the first r bits, and Inner c (state) represents the following c bits, i.e. state = Outer r (state)||Inner c (state). Outerr The (state) section is what can be affected by the input message grouping.

[0004] The security bound of the hash function constructed using the sponge pattern can be determined by its output length n (i.e., message digest length), absorption bit rate r, capacity length c, and output bit rate r′ (see Table 1).

[0005] Table 1: Safety strength of sponge structure (bits)

[0006]

[0007] As shown in Table 1, when the output length n is greater than or equal to c / 2, the security of the sponge structure against second preimage attacks depends solely on the capacity length c. In this case, increasing the output length does not improve the security of the hash function. However, hash functions are typically designed to be secure against second preimage attacks for at least the length of the output length. Therefore, to meet this requirement, the output length of such sponge hash functions must not exceed c / 2.

[0008] in, The specific steps of the algorithm are as follows:

[0009] 1) Fill the message: First, the input message msg is concatenated with the filling bits. The filling rule is calculated based on the absorption bit rate parameter r and the message length. Specifically, call The function pads the message so that the total length after padding is an integer multiple of r. Let this padded message be M.

[0010] 2) Divide the padded message into blocks: Divide M into k blocks of length r, represented as a tuple: Each m i is a two-element string of length r.

[0011] 3) Initialize the internal state: Initialize the state variable state to an all-0 bit string of length b.

[0012] 4) Absorb messages block by block. For each block m i (From i=0 to k-1) perform the following operations: i Concatenate with a bit string of all 0s of length c to get a bit string of length b; XOR state with the bit string bit by bit; then apply the permutation function to state Get the new status.

[0013] 5) Initialize the output string: define the output string Z as an empty string for subsequent cascade results.

[0014] 6) Perform the "squeeze" operation of the summary. When the output length Z has not yet reached the required length n bits, repeatedly perform the following steps: Take the first r bits from the current state ′ Bit, denoted as Trunc r′ (state); cascade this part of the data to the end of Z; then apply the permutation function to state again Update status.

[0015] 7) Return the final output summary result: When the length of Z reaches or exceeds n bits, take the first n bits as the final hash value output and return Trunc n (Z).

[0016] The specific steps of the message padding algorithm Pad are as follows:

[0017] 1) Calculate the number j of zeros to be padded, specifically: j = (r-bitLen-2) mod r, where bitLen is the bit length of the input message and r is the absorbed bit rate.

[0018] 2) Construct a padding string p, whose format is: first add a bit 1, then add j bits 0, and finally add a bit 1. That is: p = 1||0 j ||1.

[0019] 3) Return the padded bit string p. Summary of the Invention

[0020] To overcome the security-efficiency trade-offs of existing sponge-based hash functions, the present invention provides an improved sponge-based hash function design method. This method modifies the transformation function in the absorption phase (and squeeze phase) so that it is no longer a reversible permutation. This improves security against pre- and second-pre-image attacks without compromising efficiency or randomness.

[0021] The technical solution adopted in the present invention is as follows:

[0022] A method for enhancing the resistance of sponge structure hash functions to pre-image and second pre-image attacks is proposed. A feed-forward mechanism is used to improve the transformation function in the sponge structure, thereby increasing the output summary length without affecting the computational efficiency, thereby improving the security against pre-image and second pre-image attacks.

[0023] Furthermore, the use of a feedforward mechanism to improve the transformation function in the sponge structure includes the following steps:

[0024] 1) Define the transformation function for: Wherein P1 and P2 are preset permutation functions; and a permutation function P0 is preset;

[0025] 2) Construct the initial state W0, concatenate the first message block m0 with a string of all 0 bits of length c, and then perform bitwise XOR with a string of all 0 bits of length b:

[0026] 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0027] 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state:

[0028] 5) In the extrusion phase, output z0, z1, ..., z q-1 , for each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i );

[0029] 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0030] Furthermore, the use of a feedforward mechanism to improve the transformation function in the sponge structure includes the following steps:

[0031] 1) Define the transformation function for: Where P1 and P2 are preset permutation functions;

[0032] 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0033] 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0034] 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state:

[0035] 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the transformation function Get the next state:

[0036] 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0037] Furthermore, the use of a feedforward mechanism to improve the transformation function in the sponge structure includes the following steps:

[0038] 1) Define the transformation function for: Where P1 and P2 are preset permutation functions, x[r ′ ,…,b-1] represents the rth ′ bit to bit b-1; and a permutation function P0 is preset;

[0039] 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0040] 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0041] 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state:

[0042] 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i );

[0043] 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0044] Furthermore, the use of a feedforward mechanism to improve the transformation function in the sponge structure includes the following steps:

[0045] 1) Define the transformation function for: Where P1 and P2 are preset permutation functions, x[r ′ ,…,b-1] represents the rth ′ bit to bit b-1;

[0046] 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0047] 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0048] 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state:

[0049] 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the transformation function Get the next state:

[0050] 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0051] Furthermore, the use of a feedforward mechanism to improve the transformation function in the sponge structure includes the following steps:

[0052] 1) Define the transformation function for: Wherein P1 is a preset permutation function; and a permutation function P0 is preset;

[0053] 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0054] 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0055] 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state:

[0056] 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i );

[0057] 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0058] Furthermore, the use of a feedforward mechanism to improve the transformation function in the sponge structure includes the following steps:

[0059] 1) Define the transformation function for: Where P1 is the preset permutation function;

[0060] 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0061] 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0062] 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state:

[0063] 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i,r); then Y i Input to the transformation function Get the next state:

[0064] 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0065] A device for enhancing the sponge structure hash function against pre-image and second pre-image attacks, which is a computer, a server, etc., and includes a memory and a processor. The memory stores a computer program, and the computer program is configured to be executed by the processor. The computer program includes instructions for executing the above-mentioned method of the present invention.

[0066] A computer-readable storage medium stores a computer program, wherein the computer program implements the above method of the present invention when executed by a computer.

[0067] The beneficial effect of this invention is that by introducing a feedforward mechanism into the transformation function, it overcomes the limitations of traditional sponge-structured hash functions in terms of security and computational efficiency, achieving a better balance between security and efficiency. Without increasing computational complexity, this solution can effectively improve security against pre-image attacks and second pre-image attacks, thereby enhancing the practical value of hash functions in application scenarios such as message authentication, random number generation, and data signing. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 This is a schematic diagram of the traditional sponge structure.

[0069] Figure 2 This is a design diagram of the improved sponge structure hash function of the present invention. DETAILED DESCRIPTION

[0070] The present invention is further described in detail below through specific embodiments and drawings.

[0071] The technical solution adopted by the present invention to solve the technical problem is: using a feedforward mechanism to improve the transformation function so that under the conditions of the same state length (b bits) and output summary length n, when the maximum input message length is limited to 2 L In the case of r bits, we only need to set the capacity length to c = n + L, and the length of the absorbed bit rate is r = bnL. Thus, for a message input of length (b-2n) × k bits, we only need to perform Compared with the previous k operations, the computational complexity is smaller and the efficiency is higher.

[0072] More importantly, while maintaining the same computational efficiency (i.e., the capacity length is set to c = 2n, and the absorbed bit rate length is set to r = b-2n), the design of the present invention can increase the output summary length to 2n-L, thereby increasing the security against the pre-image attack and the second pre-image attack to 2. 2n-L , significantly better than the previous design of 2 n The safety is shown in Table 2.

[0073] Table 2: SpongeEDM hash security

[0074]

[0075] Among them, a collision attack refers to finding two different messages so that their hash values ​​are the same; a preimage attack refers to given a hash value, trying to find a message so that its hash value is equal to the given value; a second preimage attack refers to (given a message, trying to find another different message so that the hash values ​​of the two are the same.

[0076] The following is the complete technical solution of the present invention.

[0077] 1. Symbol and function representation:

[0078] F2={0,1}: represents a binary field.

[0079] Represents the set of all bit strings of length k.

[0080] n: message digest length.

[0081] c: Capacity length.

[0082] b: Indicates the length of status data.

[0083] c′: represents br′.

[0084] P0,P1,P2: arrive Random permutation of .

[0085] 2. Feedforward random function sponge structure hash function design:

[0086] Feedforward random function sponge structure hash function design is a sponge hash function design that increases security by using the feedforward random function in the absorption phase (and the extrusion phase) to increase the length of the output summary. Six complete feedforward random function sponge structure hash function examples are as follows: Figure 2 The complete process of the corresponding algorithm is as follows:

[0087] Option 1:

[0088] 1) Define the function

[0089] Define a transformation function for: P1 and P2 are preset permutation functions, and a permutation function P0 is also preset.

[0090] 2) Initialize the internal state W0:

[0091] Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0092] 3) Absorption phase (from block 1 to block p-1):

[0093] For each i=0 to p-2, do the following:

[0094] The current state W i Passing in a function

[0095] Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0096] 4) The last absorption:

[0097] The last intermediate state W p-1 Input to function , we get the initial output state:

[0098] 5) Squeeze phase (output z0, z1, ..., z q-1 ):

[0099] For each i=0 to q-1, repeat the following operation:

[0100] From the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r);

[0101] Then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i ).

[0102] 6) Output the final result:

[0103] Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0104] Option 2:

[0105] 1) Define the function

[0106] Define a transformation function for: Where P1 and P2 are preset permutation functions.

[0107] 2) Initialize the internal state W0:

[0108] Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0109] 3) Absorption phase (from block 1 to block p-1):

[0110] For each i=0 to p-2, do the following:

[0111] The current state W i Passing in a function

[0112] Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0113] 4) The last absorption:

[0114] The last intermediate state W p-1 Input to function , we get the initial output state:

[0115] 5) Squeeze phase (output z0, z1, ..., z q-1 ):

[0116] For each i=0 to q-1, repeat the following operation:

[0117] From the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r);

[0118] Then Y iInput to the transformation function Get the next state:

[0119] 6) Output the final result:

[0120] Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0121] Option 3:

[0122] 1) Define the function

[0123] Define a transformation function for: Where P1 and P2 are preset permutation functions, x[r ′ ,…,b-1] represents the rth ′ A permutation function P0 is preset.

[0124] 2) Initialize the internal state W0:

[0125] Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0126] 3) Absorption phase (from block 1 to block p-1):

[0127] For each i=0 to p-2, do the following:

[0128] The current state W i Passing in a function

[0129] Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0130] 4) The last absorption:

[0131] The last intermediate state W p-1 Input to function , we get the initial output state:

[0132] 5) Squeeze phase (output z0, z1, ..., z q-1 ):

[0133] For each i=0 to q-1, repeat the following operation:

[0134] From the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r);

[0135] Then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i ).

[0136] 6) Output the final result:

[0137] Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0138] Option 4:

[0139] 1) Define the function

[0140] Define a transformation function for: Where P1 and P2 are preset permutation functions.

[0141] 2) Initialize the internal state W0:

[0142] Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0143] 3) Absorption phase (from block 1 to block p-1):

[0144] For each i=0 to p-2, do the following:

[0145] The current state W i Passing in a function

[0146] Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0147] 4) The last absorption:

[0148] The last intermediate state W p-1 Input to function , we get the initial output state:

[0149] 5) Squeeze phase (output z0, z1, ..., z q-1 ):

[0150] For each i=0 to q-1, repeat the following operation:

[0151] From the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r);

[0152] Then Y i Input to the transformation function Get the next state:

[0153] 6) Output the final result:

[0154] Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0155] Option 5:

[0156] 1) Define the function

[0157] Define a transformation function for: Wherein P1 is a preset permutation function, and a permutation function P0 is preset.

[0158] 2) Initialize the internal state w0:

[0159] Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0160] 3) Absorption phase (from block 1 to block p-1):

[0161] For each i=0 to p-2, do the following:

[0162] The current state W i Passing in a function

[0163] Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0164] 4) The last absorption:

[0165] The last intermediate state W p-1 Input to function , we get the initial output state:

[0166] 5) Squeeze phase (output z0, z1, ..., z q-1 ):

[0167] For each i=0 to q-1, repeat the following operation:

[0168] From the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r);

[0169] Then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i ).

[0170] 6) Output the final result:

[0171] Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0172] Option 6:

[0173] 1) Define the function

[0174] Define a transformation function for: Where P1 is the preset permutation function.

[0175] 2) Initialize the internal state w0:

[0176] Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b:

[0177] 3) Absorption phase (from block 1 to block p-1):

[0178] For each i=0 to p-2, do the following:

[0179] The current state W iPassing in a function

[0180] Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state:

[0181] 4) The last absorption:

[0182] The last intermediate state W p-1 Input to function , we get the initial output state:

[0183] 5) Squeeze phase (output z0, z1, ..., z q-1 ):

[0184] For each i=0 to q-1, repeat the following operation:

[0185] From the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r);

[0186] Then Y i Input to the transformation function Get the next state:

[0187] 6) Output the final result:

[0188] Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

[0189] The replacement functions in the above solutions 1-6 can be selected according to the actual needs in different application scenarios.

[0190] In one embodiment of the present invention, Figure 1 The parameters in are as follows:

[0191] n=512, b=1600, c=576, r=1024,

[0192]

[0193]

[0194] The ι, χ, π, ρ, and θ functions are all mapping functions defined in the SHA-3 standard, and the message padding method is also consistent with the SHA-3 standard, that is, 10…01.

[0195] In this configuration, schemes 1-6 can provide 256 bits of anti-collision security, 512 bits of anti-preimage and anti-second preimage security (with a maximum input message length limit of 2 64 *1024 bits), then for an input message of 1315 bits, it needs to be padded into two message blocks under the scheme of the present invention: 1315 + 733 = 2 * 1024; with the same security, SHA-3-512 needs to perform the absorption phase of three message blocks, i.e. 1315 + 413 = 3 * 576.

[0196] The present invention can be used in fields such as message authentication, random number generation, and data signature.

[0197] For example, for message authentication, the method of the present invention can be used to process the key and the message to obtain a message authentication code, thereby verifying the integrity and source authenticity of the message.

[0198] For example, for random number generation, the method of the present invention can be used to process the seed and the personalized character string to obtain a pseudo-random bit sequence, thereby generating high-quality random numbers.

[0199] For example, for data signatures, the method of the present invention can be used to process the message to be signed to obtain a message digest, thereby ensuring the compactness and tamper-proofness of the signature.

[0200] Another embodiment of the present invention provides a device for enhancing the sponge structure hash function against pre-image and second pre-image attacks, which is a computer device (computer, server, smart phone, etc.), which includes a memory and a processor, the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing each step in the method of the present invention.

[0201] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk), wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the steps of the method of the present invention are implemented.

[0202] The specific embodiments of the present invention disclosed above are intended to facilitate understanding and implementation of the present invention. Those skilled in the art will appreciate that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the embodiments disclosed in this specification; the scope of protection of the present invention shall be determined by the scope defined in the claims.

Claims

1. A method for enhancing the sponge structure hash function against pre-image and second pre-image attacks, characterized in that: A feedforward mechanism is used to improve the transformation function in the sponge structure, which increases the output summary length without affecting the computational efficiency, thereby improving the security against pre-image attacks and second pre-image attacks.

2. The method according to claim 1, characterized in that The method of improving the transformation function in the sponge structure by using a feedforward mechanism includes the following steps: 1) Define the transformation function for: Wherein P1 and P2 are preset permutation functions; and a permutation function P0 is preset; 2) Construct the initial state W0, concatenate the first message block m0 with a string of all 0 bits of length c, and then perform bitwise XOR with a string of all 0 bits of length b: 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state: 4) The last absorption: the last intermediate state W p-1 Input to function In the example, we get the initial output state: Y0= 5) In the extrusion phase, output z0, z1, ..., z q-1 , for each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i ); 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

3. The method according to claim 1, characterized in that The method of improving the transformation function in the sponge structure by using a feedforward mechanism includes the following steps: 1) Define the transformation function for: Where P1 and P2 are preset permutation functions; 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b: 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state: 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state: 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the transformation function Get the next state: 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

4. The method according to claim 1, wherein The method of improving the transformation function in the sponge structure by using a feedforward mechanism includes the following steps: 1) Define the transformation function for: Where P1 and P2 are preset permutation functions, x[r ′ ,…,b-1] represents the rth ′ bit to bit b-1; and a permutation function P0 is preset; 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b: 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state: 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state: 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i ); 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

5. The method according to claim 1, characterized in that The method of improving the transformation function in the sponge structure by using a feedforward mechanism includes the following steps: 1) Define the transformation function for: Where P1 and P2 are preset permutation functions, x[r ′ ,…,b-1] represents the rth ′ bit to bit b-1; 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b: 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state: 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state: 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are intercepted as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the transformation function Get the next state: 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

6. The method according to claim 1, wherein The method of improving the transformation function in the sponge structure by using a feedforward mechanism includes the following steps: 1) Define the transformation function for: Wherein P1 is a preset permutation function; and a permutation function P0 is preset; 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b: 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state: 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state: 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are cut off as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the permutation function P0 to get the next state: Y i+1 =P0(Y i ); 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

7. The method according to claim 1, characterized in that The method of improving the transformation function in the sponge structure by using a feedforward mechanism includes the following steps: 1) Define the transformation function for: Where P1 is the preset permutation function; 2) Construct the initial state W0 by concatenating the first message block m0 with a string of all 0 bits of length c, and then performing bitwise XOR with a string of all 0 bits of length b: 3) In the absorption phase, from block 1 to block p-1, for each i=0 to p-2, perform the following operations: i Passing in a function Then concatenate it with the next message block to get the string m i+1 ||0 c Perform bitwise XOR to get the next state: 4) The last absorption: the last intermediate state W p-1 Input to function , we get the initial output state: 5) In the extrusion phase, output z0, z1, ..., z q-1 ; For each i=0 to q-1, repeat the following operations: from the current state Y i The first r bits are intercepted as the output block z i :z i =Trunc(Y i ,r); then Y i Input to the transformation function Get the next state: 6) Set all z0,z1,…,z q-1 Cascade to get z0||z1||…||z q-1 , take the first n bits as the final output.

8. A device for enhancing the protection of sponge structure hash function against pre-image and second pre-image attacks, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Variable code rate duplex mode or random number mode working method and device for realizing same

    CN122226439A