04
Second-preimage resistance (SPR) 11.12.2019 https://sphincs.org 4<br>
05
Security properties: Preimage resistance / One-wayness 11.12.2019 https://sphincs.org 5<br>
06
Quantum security worlds [Gagliardoni’17]<br>
07
QS0: Classical security 01/07/2019 https://huelsing.net 7<br>
08
QS1: Post-quantum security 01/07/2019 https://huelsing.net 8<br>
09
QS1: Post-quantum security Adversary can run local quantum computations
Adversary cannot communicate with honest parties using quantum states!
Local functions & oracles that do not contain secret information: Quantum access
Remote functions & secretly keyed oracles: Classical access 01/07/2019 https://huelsing.net 9<br>
10
QS2: Quantum security 01/07/2019 https://huelsing.net 10<br>
11
QS2: Quantum security Adversary can run local quantum computations
Adversary can communicate with honest parties using quantum states!
Local functions & oracles that do not contain secret information: Quantum access
Remote functions & secretly keyed oracles: Quantum access
This assumes a world where users have quantum computers 01/07/2019 https://huelsing.net 11<br>
12
We care about QS1 for practical applications in the foreseeable future. 01/07/2019 https://huelsing.net 12<br>
13
What does this mean for hash function security? 14.11.2019 https://sphincs.org/ 13<br>
14
Re-assess generic hardnessjoint work with Rijneveld & Song, PKC’16 14.11.2019 https://sphincs.org/ 14<br>
15
What about actual hash functions? 15<br>
16
Hash function design 16 Create fixed input size building block
Use building block to build compression function
Use „mode“ for length extension<br>
17
M-D (SHA2): Most classical results carry over (CR / OW) compression function ⇒(CR / OW) Hash 17<br>
18
Sponges (SHA3): Classical result fails in quantum setting Guido Bertoni, Joan Daemen, Michaël Peeters and Gilles Van Assche. Cryptographic Sponge Functions. 2007 18<br>
19
SHA3: Classical result fails in quantum setting 19<br>
20
Post-quantum security of Spongesjoint work with Jan Czajkowski, Leon Groot Bruinderink, Christian Schaffner, and Dominique Unruh, PQCrypto 2018 / QCRYPT 2017, Crypto’19 PQCrypto’18
Sponges are collapsing, CR, SPR, PRE if block function is random function or random one-way permutation (does not cover SHA3!)
Quantum attack that meets lower bounds
Crypto’19
Sponges are quantum-secure PRFs / MACs if keyed via block function
( = indistinguishability of random sponges)
TBD
Indifferentiability of random sponges 20<br>
21
“New” applications for hash-functionsHash-based signatures 14.11.2019 https://sphincs.org/ 21<br>
22
(Stateful) Hash-based signatures 14.11.2019 https://sphincs.org/ 22<br>
23
OTS 1-bit Lamport:
N-bit Lamport: Use N pairs of secret values. 14.11.2019 X0 X1 Y0 = H(X0) Y1 = H(X1) SK PK Sig (M=0) X0 Sig (M=1) X1 https://sphincs.org/ 23<br>
24
Merkle Signatures (from OTS to MTS) 20-1-2020 PAGE 24 H H H H H H H H H H H H H H H PK SIG = (i=2, , , , , ) SK<br>
25
Merkle Signatures (from OTS to MTS) 14.11.2019 https://sphincs.org/ 25<br>
26
Hypertree: A tree of trees 14.11.2019 https://sphincs.org/ 26<br>
27
Minimizing security assumptions 14.11.2019 https://sphincs.org/ 27<br>
28
New security requirements for hash functionsDecisional second preimage resistance (DSPR) Joint work with Daniel J. Bernstein 14.11.2019 https://sphincs.org/ 28<br>
29
OTS 1-bit Lamport:
N-bit Lamport: Use N pairs of secret values. 14.11.2019 X0 X1 Y0 = H(X0) Y1 = H(X1) SK PK Sig (M=0) X0 Sig (M=1) X1 https://sphincs.org/ 29<br>
30
Tightness loss 14.11.2019 https://sphincs.org/ 30<br>
31
Relations 11.12.2019 https://sphincs.org 31 Collision-Resistance 2nd-Preimage-Resistance One-way Assumption / Attacks Stronger assumption / easier to break weaker assumption/
harder to break Our work<br>
32
Decisional Second-Preimage Resistancejoint work with Daniel J. Bernstein, Asiacrypt 2019 14.11.2019 https://sphincs.org/ 32<br>
33
Stateless hash-based signaturesSPHINCS Joint work with Daniel J. Bernstein, Daira Hopwood, Tanja Lange, Ruben Niederhagen, Louiza Papachristodoulou, Michael Schneider, Peter Schwabe, and Zooko Wilcox-O’Hearn 14.11.2019 https://sphincs.org/ 33<br>
34
Stateless hash-based signatures [NY89,Gol87,Gol04] 14.11.2019 https://sphincs.org/ 34<br>
35
SPHINCS [BHH+15] Select index pseudorandomly
Use a few-time signature key-pair onleaves to sign messages
Few index collisions allowed
Allows to reduce tree height
Use hypertree: Use d < h.
(SPHINCS-256: h=60, d=12) 14.11.2019 FTS https://sphincs.org/ 35<br>
36
The SPHINCS+ Signature Framework Joint work with Daniel J. Bernstein, Stefan Kölbl, Ruben Niederhagen, Joost Rijneveld, Peter Schwabe<br>
37
The SPHINCS + team Jean-Philippe Aumasson, Daniel J. Bernstein, Christoph Dobraunig, Maria Eichlseder, Scott Fluhrer, Stefan-Lukas Gazdag, Andreas Hülsing, Panos Kampanakis, Stefan Kölbl, Tanja Lange, Martin M. Lauridsen, Florian Mendel, Ruben Niederhagen, Christian Rechberger, Joost Rijneveld, Peter Schwabe 14.11.2019 https://sphincs.org/ 37<br>
38
From SPHINCS to SPHINCS+ 14.11.2019 https://sphincs.org/ 38<br>
39
14.11.2019 https://sphincs.org/ 39<br>
40
Tweakable hash functions A tool for modular proofs for hash-based signatures 14.11.2019 https://sphincs.org/ 40<br>
41
Hashing for hash-based signatures(Change driven by goal to minimize security assumptions) 14.11.2019 H X Y H X Y B H X Y B K MSS XMSS XMSS-T H Y LMS SPHINCS SPHINCS+robust SPHINCS+simple Gravity-SPHINCS https://sphincs.org/ 41<br>
42
Tweakable hash function 14.11.2019 https://sphincs.org/ 42<br>
43
Required security properties(see paper for formal definitions) 14.11.2019 https://sphincs.org/ 43<br>
44
In paper Tweakable hash constructions that achieve PQ-SM-TCR & PQ-SM-DSPR
Construction 1: Standard model proof but massive public parameters
Construction 2: Construction 1 with compressed public parameters (compression needs QROM, approx. XMSS-T construction)
Construction 3: All QROM proof(simplified LMS construction) 14.11.2019 https://sphincs.org/ 44<br>
45
Security using tweakable hash 14.11.2019 https://sphincs.org/ 45<br>
46
Comparison 14.11.2019 https://sphincs.org/ 46<br>
47
14.11.2019 https://sphincs.org/ 47<br>
48
Conclusion We got several results establishing security of cryptographic hash functions in a post-quantum world. Strongest security notions are still open.
New applications for hash functions lead to new security requirements that have to be studied.
Skipped:
Security proofs in the random oracle model change entirely.
Often old security properties do not suffice (collapsing)
Although Grovers algorithm is optimal, there are still many open questions for hash functions in a post-quantum world. 14.11.2019 https://sphincs.org/ 48<br>
49
“If you’re signing something for the long-term future, and 40KB sigs is not a problem, use (stateless) hash-based sigs e.g. SPHINCS”
Vadim Lyubashevsky, 2017 14.11.2019 https://sphincs.org/ 49 30<br>