Re: Curve25519-based EC-KCDSA



David Wagner <daw-usenet@xxxxxxxxxxxxxxxxxxxxxxxx> wrote:
In other words, perhaps I should have phrased my concern in terms of
the level of assurance, rather than a binary "has a security proof" vs
"doesn't" distinction.

Ok, that muddies everything up. Then simple analysis won't help any more,
I guess.

Still, I feel that some attacks on DSA without hash function would
be interesting, because they could put a lot more stress on the hash
function. The only attack I know of generates a signature on a random
message, but since the hash function is already designed to be one-way,
that attack isn't interesting.

Unless I'm still not thinking clearly or have missed interesting attacks
(which is likely), it seems possible there aren't any interesting attacks
on DSA without hash function.

I don't think the "mostly invertible"
bit is necessary.

The "mostly invertible" bit is a heuristic suggestion that any scheme that
relies only on a collision resistant hash function (not random oracle)
to process the message must probably be secure without that hash function.

--
Kristian Gjøsteen
.



Relevant Pages

  • Re: Two questions on Stream Ciphers like ARC4 and L14
    ... problems may reveal themselves as a result of timing attacks. ... Security against chosen-ciphertext attack means this sort of thing can't ... > able to use an IV without a cryptographic hash function, ... provably secure if all the keys are generated in a way which is `hard' ...
    (sci.crypt)
  • Re: cryptographic hash functions versus non-cryptographic hash functions
    ... as the block size of the hash function, it's also resistant again preimage ... We are talking about preimage attacks. ...
    (sci.crypt)
  • A Fast New Hash Function
    ... the author studies the fast cryptographic hash function. ... known collision attacks. ... the author proves that the TWOBLOCK ...
    (sci.crypt)
  • Re: cryptographic hash functions versus non-cryptographic hash functions
    ... as the block size of the hash function, it's also resistant again preimage ... attacks. ... the best preimage attack would be a brute force search. ...
    (sci.crypt)
  • new NIST FIPS DSS draft
    ... would like to ask about the following excerpt, ... Selection of Parameter Sizes and Hash Functions for DSA ... A hash function is required during the generation of digital ... The security strength of the hash function ...
    (sci.crypt)