{[ promptMessage ]}

Bookmark it

{[ promptMessage ]}

03_hash - Hashes and Integrity Peter Sjdin [email protected] Based...

This preview shows pages 1–6. Sign up to view the full content.

1 Hashes and Integrity Peter Sjödin Based on material by Vitaly Shmatikov, Univ. of Texas, and by the previous course teachers

This preview has intentionally blurred sections. Sign up to view the full version.

View Full Document
2 Motivation: Integrity Software manufacturer wants to ensure that the executable file is received by users without modification. It sends out the file to users and publishes its hash in NY Times. The goal is integrity , not secrecy Idea: given goodFile and hash(goodFile), very hard to find badFile such that hash(goodFile)=hash(badFile) goodFile BigFirm™ User VIRUS badFile The Times hash(goodFile)
3 Integrity vs. Secrecy Integrity: attacker cannot tamper with message • Encryption per se does not guarantee integrity Intuition: attacker may able to modify message under encryption without learning what it is This is recognized by industry standards (e.g., PKCS) “RSA encryption is intended primarily to provide confidentiality… It is not intended to provide integrity” (from RSA Labs Bulletin) Some encryption schemes provide secrecy AND integrity

This preview has intentionally blurred sections. Sign up to view the full version.

View Full Document
4 Motivation: Authentication Alice wants to make sure that nobody modifies message in transit Ensures both integrity and authentication (why?) Idea: given msg, very hard to compute hash(KEY,msg) without KEY Very easy with KEY msg, hash(KEY,msg) Alice Bob KEY KEY
5 Hash Functions: Main Idea bit strings of any length n-bit bit strings . . . . . x’ x’’ x y’ y hash function H H is a lossy compression function Collisions: H(x)=H(x’) for some inputs x, x’ Result of hashing should “look random” Intuition: half of digest bits are “1”; any bit in digest is “1” half the time Any two outputs should be uncorrelated – differ by half of the bits Cryptographic hash function needs a few properties… message “digest” message

This preview has intentionally blurred sections. Sign up to view the full version.

View Full Document
This is the end of the preview. Sign up to access the rest of the document.

{[ snackBarMessage ]}

What students are saying

• As a current student on this bumpy collegiate pathway, I stumbled upon Course Hero, where I can find study resources for nearly all my courses, get online help from tutors 24/7, and even share my old projects, papers, and lecture notes with other students.

Kiran Temple University Fox School of Business ‘17, Course Hero Intern

• I cannot even describe how much Course Hero helped me this summer. It’s truly become something I can always rely on and help me. In the end, I was not only able to survive summer classes, but I was able to thrive thanks to Course Hero.

Dana University of Pennsylvania ‘17, Course Hero Intern

• The ability to access any university’s resources through Course Hero proved invaluable in my case. I was behind on Tulane coursework and actually used UCLA’s materials to help me move forward and get everything together on time.

Jill Tulane University ‘16, Course Hero Intern