ご案内 入会して研究会活動をもっとお得に!研究会参加費・年間登録費が会員価格になります。
お知らせ 【重要】研究会参加費の支払いおよび原稿アップロード手続きの変更に関するご案内
電子情報通信学会 研究会発表申込システム
講演論文 詳細
技報閲覧サービス
[ログイン]
技報アーカイブ
 トップに戻る 前のページに戻る   [Japanese] / [English] 

講演抄録/キーワード
講演名 2023-03-15 14:55
Keccak[r = 40, c = 160, nr = 2]における原像計算時間に関する実験
戚 莘鈺藤岡 淳神奈川大)・青木和麻呂文教大IT2022-131 ISEC2022-110 WBS2022-128 RCC2022-128
抄録 (和) Keccak は, アメリカ国立標準技術研究所 (NIST) により SHA-3 として選出された暗号学的な Hash 関数の元となっている技術である. Keccak の内部状態は, 入出力に直接影響する部分のレート (r), 入出力に直接は影響しない部分のキャパシティ (c) からなり, 計 r+ c ビットである. ブロック置換関数により, 内部状態をかき混ぜることが nr回
(ラウンド数) 行われ, 出力長に応じて更にブロック置換が繰り返される (提案者は, Keccak[r = 40, c = 160, ?nr= 1] のように表現している). 本研究では, まだ有効な攻撃方法がない Keccak のパラメータ内部状態における c/(r + c) が大きい原像攻撃耐性を評価することを目的とする. 入力の (一部を) 限定した Keccak[r = 40, c = 160, nr = 2] への原像攻撃を行った. そして, Keccak[r = 20, c = 80, nr = 2] に対する, 項 (求められる変数) の数が小さいところで, Hash 値に関する連立方程式の最大次数および計算時間の関係を考察した. その結果, 1) 入力を限定 (前半と後半が同じもの, ないし, 後半がすべて 0) した場合に, 原像攻撃に成功する, 2) 変数が少ない場合に, その最大次数が変数の数と一致しない場合がある, 3) 原像が存在する場合には, Hash 値の前半のみを利用して原像を求め, 再度, Hash して後半と一致することを確認する攻撃を利用すれば, 攻撃時間を削減することが可能である, ことが判明した. 
(英) Keccak is the technology behind the cryptographic hash function selected by the National Institute of Standards and Technology (NIST) as SHA-3. Keccak has an internal state with a total length of r + c bits, which consists of a rate (r) part that directly affects input/output and a capacity (c) part that does directly not affect input/output. With the block replacement function, the internal state can be stirred up nr times (number of rounds), and further block replacement is repeated according to the output length (the proposers express it as Keccak[r = 40, c = 160, nr = 1]). In this paper, we aim to evaluate the pre-image attack resistance of Keccak, whose parameters and internal state pair c/(r + c) are large, for which we do not yet have an effective attack method. We performed the pre-image attack on Keccak[r = 40, c= 160, nr = 2], although the input is limited. Then, for Keccak[r = 20, c = 80, nr = 2], where the number of terms (variables in simultaneous equations) is small,
we consider the relation between the maximum order and computation time of the simultaneous equations for Hash values. As a result, it was found that 1) the pre-image attack succeeds when the input is limited (the first half and the second half are the
same, or the second half is all 0), 2) when the number of variables is small, the maximum order may not match the number of variables, and 3) when the pre-image exists, the attack time can be reduced by using only the first half of the Hash value to obtain the pre-image and then Hashing again to confirm that the second half matches the first half. 3) If the pre-image exists, it is possible to reduce the attack time by using only the first half of the Hash value to find the pre-image, and then Hash again toconfirm that the second half is the same.
キーワード (和) Keccak / 原像攻撃耐性 / キャパシティ比 / 最適化ソルバ / / / /  
(英) Keccak / pre-image resistance / capacity ratio / optimization solver / / / /  
文献情報 信学技報, vol. 122, no. 428, ISEC2022-110, pp. 398-403, 2023年3月.
資料番号 ISEC2022-110 
発行日 2023-03-07 (IT, ISEC, WBS, RCC) 
ISSN Online edition: ISSN 2432-6380
著作権に
ついて
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034)
PDFダウンロード IT2022-131 ISEC2022-110 WBS2022-128 RCC2022-128

研究会情報
研究会 RCC ISEC IT WBS  
開催期間 2023-03-14 - 2023-03-15 
開催地(和) 山口大学常盤キャンパス 
開催地(英)  
テーマ(和) RCC・ISEC・IT・WBS合同研究会 
テーマ(英)  
講演論文情報の詳細
申込み研究会 ISEC 
会議コード 2023-03-RCC-ISEC-IT-WBS 
本文の言語 日本語 
タイトル(和) Keccak[r = 40, c = 160, nr = 2]における原像計算時間に関する実験 
サブタイトル(和)  
タイトル(英) Experiments on pre-image computation time in Keccak[r = 40, c = 160, nr = 2] 
サブタイトル(英)  
キーワード(1)(和/英) Keccak / Keccak  
キーワード(2)(和/英) 原像攻撃耐性 / pre-image resistance  
キーワード(3)(和/英) キャパシティ比 / capacity ratio  
キーワード(4)(和/英) 最適化ソルバ / optimization solver  
キーワード(5)(和/英) /  
キーワード(6)(和/英) /  
キーワード(7)(和/英) /  
キーワード(8)(和/英) /  
第1著者 氏名(和/英/ヨミ) 戚 莘鈺 / Xinyu Qi / セキ シンギョク
第1著者 所属(和/英) 神奈川大学 (略称: 神奈川大)
Kanagawa University (略称: Kanagawa Univ)
第2著者 氏名(和/英/ヨミ) 藤岡 淳 / Atsushi Fujioka / フジオカ アツシ
第2著者 所属(和/英) 神奈川大学 (略称: 神奈川大)
Kanagawa University (略称: Kanagawa Univ)
第3著者 氏名(和/英/ヨミ) 青木 和麻呂 / Kazumaro Aoki / アオキ カズマロ
第3著者 所属(和/英) 文教大学 (略称: 文教大)
BUNKYO University (略称: BUNKYO Univ)
第4著者 氏名(和/英/ヨミ) / /
第4著者 所属(和/英) (略称: )
(略称: )
第5著者 氏名(和/英/ヨミ) / /
第5著者 所属(和/英) (略称: )
(略称: )
第6著者 氏名(和/英/ヨミ) / /
第6著者 所属(和/英) (略称: )
(略称: )
第7著者 氏名(和/英/ヨミ) / /
第7著者 所属(和/英) (略称: )
(略称: )
第8著者 氏名(和/英/ヨミ) / /
第8著者 所属(和/英) (略称: )
(略称: )
第9著者 氏名(和/英/ヨミ) / /
第9著者 所属(和/英) (略称: )
(略称: )
第10著者 氏名(和/英/ヨミ) / /
第10著者 所属(和/英) (略称: )
(略称: )
第11著者 氏名(和/英/ヨミ) / /
第11著者 所属(和/英) (略称: )
(略称: )
第12著者 氏名(和/英/ヨミ) / /
第12著者 所属(和/英) (略称: )
(略称: )
第13著者 氏名(和/英/ヨミ) / /
第13著者 所属(和/英) (略称: )
(略称: )
第14著者 氏名(和/英/ヨミ) / /
第14著者 所属(和/英) (略称: )
(略称: )
第15著者 氏名(和/英/ヨミ) / /
第15著者 所属(和/英) (略称: )
(略称: )
第16著者 氏名(和/英/ヨミ) / /
第16著者 所属(和/英) (略称: )
(略称: )
第17著者 氏名(和/英/ヨミ) / /
第17著者 所属(和/英) (略称: )
(略称: )
第18著者 氏名(和/英/ヨミ) / /
第18著者 所属(和/英) (略称: )
(略称: )
第19著者 氏名(和/英/ヨミ) / /
第19著者 所属(和/英) (略称: )
(略称: )
第20著者 氏名(和/英/ヨミ) / /
第20著者 所属(和/英) (略称: )
(略称: )
第21著者 氏名(和/英/ヨミ) / /
第21著者 所属(和/英) (略称: )
(略称: )
第22著者 氏名(和/英/ヨミ) / /
第22著者 所属(和/英) (略称: )
(略称: )
第23著者 氏名(和/英/ヨミ) / /
第23著者 所属(和/英) (略称: )
(略称: )
第24著者 氏名(和/英/ヨミ) / /
第24著者 所属(和/英) (略称: )
(略称: )
第25著者 氏名(和/英/ヨミ) / /
第25著者 所属(和/英) (略称: )
(略称: )
第26著者 氏名(和/英/ヨミ) / /
第26著者 所属(和/英) (略称: )
(略称: )
第27著者 氏名(和/英/ヨミ) / /
第27著者 所属(和/英) (略称: )
(略称: )
第28著者 氏名(和/英/ヨミ) / /
第28著者 所属(和/英) (略称: )
(略称: )
第29著者 氏名(和/英/ヨミ) / /
第29著者 所属(和/英) (略称: )
(略称: )
第30著者 氏名(和/英/ヨミ) / /
第30著者 所属(和/英) (略称: )
(略称: )
第31著者 氏名(和/英/ヨミ) / /
第31著者 所属(和/英) (略称: )
(略称: )
第32著者 氏名(和/英/ヨミ) / /
第32著者 所属(和/英) (略称: )
(略称: )
第33著者 氏名(和/英/ヨミ) / /
第33著者 所属(和/英) (略称: )
(略称: )
第34著者 氏名(和/英/ヨミ) / /
第34著者 所属(和/英) (略称: )
(略称: )
第35著者 氏名(和/英/ヨミ) / /
第35著者 所属(和/英) (略称: )
(略称: )
第36著者 氏名(和/英/ヨミ) / /
第36著者 所属(和/英) (略称: )
(略称: )
講演者 第1著者 
発表日時 2023-03-15 14:55:00 
発表時間 25分 
申込先研究会 ISEC 
資料番号 IT2022-131, ISEC2022-110, WBS2022-128, RCC2022-128 
巻番号(vol) vol.122 
号番号(no) no.427(IT), no.428(ISEC), no.429(WBS), no.430(RCC) 
ページ範囲 pp.398-403 
ページ数
発行日 2023-03-07 (IT, ISEC, WBS, RCC) 


[研究会発表申込システムのトップページに戻る]

[電子情報通信学会ホームページ]


IEICE / 電子情報通信学会