Leth(x)be acollision resistanthash function. Define another hash functionh′(x)ash′(x)={0l,...
但是实际上根据CRHF定义,如果一个函数是抗碰撞的,指的是任何多项式时间敌手,不能在多项式时间内,以不可忽略概率找到x1≠x2,且h(x1)=h(x2),这样即为collision resistant。这代表可能存在不同输入但是对应相同输出,只要无法在多项式时间内以不可忽略概率找到即可满足条件。对于h'(x),如果仅仅存在一组碰撞值...
Second-preimage resistanceWe propose a new construction for Merkle authentication trees which does not require collision resistant hash functions; in contrast with previous constructions that attempted to avoid the dependency on collision resistance, our technique enjoys provable security assuming the well-...