{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,1,9]],"date-time":"2025-01-09T05:22:04Z","timestamp":1736400124339,"version":"3.32.0"},"publisher-location":"Berlin, Heidelberg","reference-count":46,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540338512"},{"type":"electronic","value":"9783540338529"}],"license":[{"start":{"date-parts":[[2006,1,1]],"date-time":"2006-01-01T00:00:00Z","timestamp":1136073600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11745853_10","type":"book-chapter","created":{"date-parts":[[2006,4,13]],"date-time":"2006-04-13T09:18:58Z","timestamp":1144919938000},"page":"140-156","source":"Crossref","is-referenced-by-count":14,"title":["Collision-Resistant No More: Hash-and-Sign Paradigm Revisited"],"prefix":"10.1007","author":[{"given":"Ilya","family":"Mironov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Biham, E., Chen, R., Joux, A., Carribault, P., Lemuet, C., Jalby, W.: Collisions of SHA-0 and reduced SHA-1. In: Cramer [Cra05], pp. 36\u201357 (2005)","DOI":"10.1007\/11426639_3"},{"key":"10_CR2","series-title":"Lecture Notes in Computer Science","first-page":"1","volume-title":"Advances in Cryptology - CRYPTO \u201996","author":"M. Bellare","year":"1996","unstructured":"Bellare, M., Canetti, R., Krawczyk, H.: Keying hash functions for message authentication. In: Koblitz, N. (ed.) CRYPTO 1996. LNCS, vol.\u00a01109, pp. 1\u201315. Springer, Heidelberg (1996)"},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"Blum, M., Micali, S.: How to generate cryptographically strong sequences of pseudo random bits. In: 23rd Annual Symposium on Foundations of Computer Science, Chicago, Illinois, November 3\u20135, 1982, pp. 112\u2013117. IEEE, Los Alamitos (1982)","DOI":"10.1109\/SFCS.1982.72"},{"key":"10_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"480","DOI":"10.1007\/3-540-69053-0_33","volume-title":"Advances in Cryptology - EUROCRYPT \u201997","author":"N. Bari\u0107","year":"1997","unstructured":"Bari\u0107, N., Pfitzmann, B.: Collision-free accumulators and fail-stop signature schemes without trees. In: Fumy, W. (ed.) EUROCRYPT 1997. LNCS, vol.\u00a01233, pp. 480\u2013494. Springer, Heidelberg (1997)"},{"key":"10_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1007\/978-3-540-46588-1_19","volume-title":"Public Key Cryptography","author":"E.F. Brickell","year":"2000","unstructured":"Brickell, E.F., Pointcheval, D., Vaudenay, S., Yung, M.: Design validations for discrete logarithm based signature schemes. In: Imai, H., Zheng, Y. (eds.) PKC 2000. LNCS, vol.\u00a01751, pp. 276\u2013292. Springer, Heidelberg (2000)"},{"key":"10_CR6","doi-asserted-by":"crossref","unstructured":"Bellare, M., Rogaway, P.: Random oracles are practical: A paradigm for designing efficient protocols. In: ACM Conference on Computer and Communications Security, pp. 62\u201373 (1993)","DOI":"10.1145\/168588.168596"},{"key":"10_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"399","DOI":"10.1007\/3-540-68339-9_34","volume-title":"Advances in Cryptology - EUROCRYPT \u201996","author":"M. Bellare","year":"1996","unstructured":"Bellare, M., Rogaway, P.: The exact security of digital signatures\u2014how to sign with RSA and Rabin. In: Maurer, U.M. (ed.) EUROCRYPT 1996. LNCS, vol.\u00a01070, pp. 399\u2013416. Springer, Heidelberg (1996)"},{"key":"10_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"470","DOI":"10.1007\/BFb0052256","volume-title":"Advances in Cryptology - CRYPTO \u201997","author":"M. Bellare","year":"1997","unstructured":"Bellare, M., Rogaway, P.: Collision-resistant hashing: Towards making UOWHFs practical. In: Kaliski Jr., B.S. (ed.) CRYPTO 1997. LNCS, vol.\u00a01294, pp. 470\u2013484. Springer, Heidelberg (1997)"},{"key":"10_CR9","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology - CRYPTO \u201989","year":"1990","unstructured":"Brassard, G. (ed.): CRYPTO 1989. LNCS, vol.\u00a0435. Springer, Heidelberg (1990)"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Coron, J.-S., Dodis, Y., Malinaud, C., Puniya, P.: Merkle-Damg\u00e5rd revisited: How to construct a hash function. In: Shoup [Sho05], pp. 430\u2013448 (2005)","DOI":"10.1007\/11535218_26"},{"issue":"1","key":"10_CR11","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/s10623-003-6154-z","volume":"35","author":"D.R.L. Brown","year":"2005","unstructured":"Brown, D.R.L.: Generic groups, collision resistance, and ECDSA. Designs, Codes and Cryptography\u00a035(1), 119\u2013152 (2005)","journal-title":"Designs, Codes and Cryptography"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Coron, J.-S.: Optimal security proofs for PSS and other signature schemes. In: Knudsen [Knu02], pp. 272\u2013287 (2002)","DOI":"10.1007\/3-540-46035-7_18"},{"key":"10_CR13","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","year":"2005","unstructured":"Cramer, R. (ed.): EUROCRYPT 2005. LNCS, vol.\u00a03494. Springer, Heidelberg (2005)"},{"issue":"3","key":"10_CR14","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1145\/357830.357847","volume":"3","author":"R. Cramer","year":"2000","unstructured":"Cramer, R., Shoup, V.: Signature schemes based on the strong RSA assumption. ACM Trans. on Information and System Security (TISSEC)\u00a03(3), 161\u2013185 (2000)","journal-title":"ACM Trans. on Information and System Security (TISSEC)"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Damg\u00e5rd, I.: A design principle for hash functions. In: Brassard [Bra90], pp. 416\u2013427 (1990)","DOI":"10.1007\/0-387-34805-0_39"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Dodis, Y., Oliveira, R., Pietrzak, K.: On the generic insecurity of the full domain hash. In: Shoup [Sho05], pp. 449\u2013466 (2005)","DOI":"10.1007\/11535218_27"},{"key":"10_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/3-540-47721-7_12","volume-title":"Advances in Cryptology - CRYPTO \u201986","author":"A. Fiat","year":"1987","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: Practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO 1986. LNCS, vol.\u00a0263, pp. 186\u2013194. Springer, Heidelberg (1987)"},{"key":"10_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1007\/3-540-36288-6_9","volume-title":"Public Key Cryptography - PKC 2003","author":"M. Fischlin","year":"2002","unstructured":"Fischlin, M.: The Cramer-Shoup Strong-RSA signature scheme revisited. In: Desmedt, Y.G. (ed.) PKC 2003. LNCS, vol.\u00a02567, pp. 116\u2013129. Springer, Heidelberg (2002)"},{"key":"10_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/3-540-48910-X_9","volume-title":"Advances in Cryptology - EUROCRYPT \u201999","author":"R. Gennaro","year":"1999","unstructured":"Gennaro, R., Halevi, S., Rabin, T.: Secure hash-and-sign signatures without the random oracle. In: Stern, J. (ed.) EUROCRYPT 1999. LNCS, vol.\u00a01592, pp. 123\u2013139. Springer, Heidelberg (1999)"},{"key":"10_CR20","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1988","unstructured":"Goldwasser, S., Micali, S., Rivest, R.L.: A digital signature scheme secure against adaptive chosen-message attacks. SIAM Journal on Computing\u00a017, 281\u2013308 (1988)","journal-title":"SIAM Journal on Computing"},{"key":"10_CR21","doi-asserted-by":"crossref","unstructured":"Halevi, S., Krawczyk, H.: Strengthening digital signatures via randomized hashing. Internet-Draft, Crypto Forum Research Group (May 2005)","DOI":"10.1007\/11818175_3"},{"key":"10_CR22","unstructured":"Halevi, S., Krawczyk, H.: Strengthening digital signatures via randomized hashing. In: Talk at Cryptographic Hash Workshop (NIST), October 31\u2013November 1 (2005)"},{"key":"10_CR23","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology - EUROCRYPT 2002","year":"2002","unstructured":"Knudsen, L.R. (ed.): EUROCRYPT 2002. LNCS, vol.\u00a02332. Springer, Heidelberg (2002)"},{"key":"10_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/978-3-540-30539-2_15","volume-title":"Advances in Cryptology - ASIACRYPT 2004","author":"D. Hong","year":"2004","unstructured":"Hong, D., Preneel, B., Lee, S.: Higher order universal oneway hash functions. In: Lee, P.J. (ed.) ASIACRYPT 2004. LNCS, vol.\u00a03329, pp. 201\u2013213. Springer, Heidelberg (2004)"},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Kelsey, J., Schneier, B.: Second preimages on n-bit hash functions for much less than 2n work. In: Cramer [Cra05], pp. 474\u2013490 (2005)","DOI":"10.1007\/11426639_28"},{"key":"10_CR26","doi-asserted-by":"crossref","unstructured":"Merkle, R.C.: One way hash functions and DES. In: Brassard [Bra90], pp. 428\u2013446 (1990)","DOI":"10.1007\/0-387-34805-0_40"},{"key":"10_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"166","DOI":"10.1007\/3-540-44987-6_11","volume-title":"Advances in Cryptology - EUROCRYPT 2001","author":"I. Mironov","year":"2001","unstructured":"Mironov, I.: Hash functions: From Merkle-Damg\u00e5ard to Shoup. In: Pfitzmann, B. (ed.) EUROCRYPT 2001. LNCS, vol.\u00a02045, pp. 166\u2013181. Springer, Heidelberg (2001)"},{"key":"10_CR28","unstructured":"NESSIE Consortium. Performance of optimized implementations of the NESSIE primitives, version 2.0. Deliverable report D21, NES\/DOC\/TEC\/WP6\/D21\/2 (February 2003)"},{"key":"10_CR29","unstructured":"NIST. Secure hash standard. FIPS PUB 180-1, National Institute of Standards and Technology (April 1995)"},{"key":"10_CR30","doi-asserted-by":"crossref","unstructured":"Nakajima, J., Matsui, M.: Performance analysis and parallel implementation of dedicated hash functions. In: Knudsen [Knu02], pp. 165\u2013180 (2002)","DOI":"10.1007\/3-540-46035-7_11"},{"issue":"3","key":"10_CR31","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s00145-002-0021-3","volume":"15","author":"P.Q. Nguyen","year":"2002","unstructured":"Nguyen, P.Q., Shparlinski, I.E.: The insecurity of the digital signature algorithm with partially known nonces. J. Cryptology\u00a015(3), 151\u2013176 (2002)","journal-title":"J. Cryptology"},{"key":"10_CR32","doi-asserted-by":"crossref","unstructured":"Naor, M., Yung, M.: Universal one-way hash functions and their cryptographic applications. In: Proceedings of the Twenty First Annual ACM Symposium on Theory of Computing, May 15\u201317, pp. 33\u201343 (1989)","DOI":"10.1145\/73007.73011"},{"key":"10_CR33","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology - EUROCRYPT 2000","year":"2000","unstructured":"Preneel, B. (ed.): EUROCRYPT 2000. LNCS, vol.\u00a01807. Springer, Heidelberg (2000)"},{"key":"10_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11593447_1","volume-title":"Advances in Cryptology - ASIACRYPT 2005","author":"P. Paillier","year":"2005","unstructured":"Paillier, P., Vergnaud, D.: Discrete-log-based signatures not be equivalent to discrete log. In: Roy, B. (ed.) ASIACRYPT 2005. LNCS, vol.\u00a03788, pp. 1\u201320. Springer, Heidelberg (2005)"},{"key":"10_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1007\/3-540-38424-3_22","volume-title":"Advances in Cryptology - CRYPTO \u201990","author":"R.L. Rivest","year":"1991","unstructured":"Rivest, R.L.: The MD4 message digest algorithm. In: Menezes, A., Vanstone, S.A. (eds.) CRYPTO 1990. LNCS, vol.\u00a0537, pp. 303\u2013311. Springer, Heidelberg (1991)"},{"key":"10_CR36","doi-asserted-by":"crossref","unstructured":"Rompel, J.: One-way functions are necessary and sufficient for secure signatures. In: Proceedings of the Twenty Second Annual ACM Symposium on Theory of Computing, May 14\u201316, pp. 387\u2013394 (1990)","DOI":"10.1145\/100216.100269"},{"key":"10_CR37","doi-asserted-by":"crossref","unstructured":"Sarkar, P.: Masking based domain extenders for UOWHFs: Bounds and constructions. Cryptology ePrint Archive, Report 2003\/225 (2003), http:\/\/eprint.iacr.org\/","DOI":"10.1007\/978-3-540-30539-2_14"},{"key":"10_CR38","doi-asserted-by":"crossref","unstructured":"Shoup, V.: A composition theorem for universal one-way hash functions. In: Preneel [Pre00], pp. 445\u2013452 (2000)","DOI":"10.1007\/3-540-45539-6_32"},{"key":"10_CR39","doi-asserted-by":"crossref","unstructured":"Shoup, V.: Using hash functions as a hedge against chosen ciphertext attack. In: Preneel [Pre00], pp. 275\u2013288 (2000)","DOI":"10.1007\/3-540-45539-6_19"},{"key":"10_CR40","unstructured":"Shoup, V.: Sequences of games: a tool for taming complexity in security proofs. Cryptology ePrint Archive, Report 2004\/332 (2004), http:\/\/eprint.iacr.org\/"},{"key":"10_CR41","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","year":"2005","unstructured":"Shoup, V. (ed.): CRYPTO 2005. LNCS, vol.\u00a03621. Springer, Heidelberg (2005)"},{"key":"10_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"334","DOI":"10.1007\/BFb0054137","volume-title":"Advances in Cryptology - EUROCRYPT \u201998","author":"D.R. Simon","year":"1998","unstructured":"Simon, D.R.: Finding collisions on a one-way street: Can secure hash functions be based on general assumptions? In: Nyberg, K. (ed.) EUROCRYPT 1998. LNCS, vol.\u00a01403, pp. 334\u2013345. Springer, Heidelberg (1998)"},{"key":"10_CR43","unstructured":"Schweinberger, T., Shoup, V.: ACE: The advanced cryptographic engine (2000) (manuscript), http:\/\/shoup.net\/papers\/ace.pdf"},{"key":"10_CR44","doi-asserted-by":"crossref","unstructured":"Wang, X., Yu, H.: How to break MD5 and other hash functions. In: Cramer [Cra05], pp. 19\u201335 (2005)","DOI":"10.1007\/11426639_2"},{"key":"10_CR45","doi-asserted-by":"crossref","unstructured":"Wang, X., Yin, Y.L., Yu, H.: Finding collisions in the full SHA-1. In: Shoup [Sho05], pp. 17\u201336 (2005)","DOI":"10.1007\/11535218_2"},{"key":"10_CR46","doi-asserted-by":"crossref","unstructured":"Wang, X., Yu, H., Yin, Y.L.: Efficient collision search attacks on SHA-0. In: Shoup [Sho05], pp. 1\u201316 (2005)","DOI":"10.1007\/11535218_1"}],"container-title":["Lecture Notes in Computer Science","Public Key Cryptography - PKC 2006"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11745853_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,8]],"date-time":"2025-01-08T11:06:20Z","timestamp":1736334380000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11745853_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540338512","9783540338529"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/11745853_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2006]]}}}