Hardware Evaluation of The Hash Function Hamsi

نویسنده

  • Junfeng Fan
چکیده

This document describes ASIC and FPGA implementations of the hash function Hamsi. The results show that Hamsi can be efficiently implemented in hardware with small area. We also point out several optimization methods targeting different design goals. 1 Design Guideline The current implementations are straightforward realizations of the Hamsi hash function family. In other words, higher throughput or lower footprint should be achievable by applying certain optimization methods. 2 Architecture The hash function Hamsi is based on a message expansion function and iterated transformations. Let Mi and iv denote a message block and the initial value, respectively, then the hash value h is computed as follows: hi = (T ◦ P ◦ C(E(Mi), hi−1))⊕ hi−1, h0 = iv, 0 < i < l (1) h = (T ◦ Pf ◦ C(E(Ml), hl−1))⊕ hl−1 (2) Here E,C, P, T denote Message Expansion, Concatenation, Non-linear Permutation and Truncation, respectively. Non-linear Permutation P (Pf for the last message block) consists of three layers, namely, addition of constants and a counter, substitution and diffusion layer. Pf differs from P in only constants and the number of rounds. The complete description of Hamsi can be obtained from the specification [4]. Figure 1 shows the architecture of the Hamsi coprocessor. The coprocessor consists of a main controller, combinational logic for E,C, P, T , and three registers. The last message block is also hashed with the same circuit, while it use different constant and more rounds are applied. Note that we assume that message padding is performed by the main CPU, the Hamsi coprocessor reads the message from a shared memory. The results is in the cvalue register and shifted out word-by-word. Message Expansion Concatenation

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Near Collisions for the Compress Function of Hamsi-256 Found by Genetic Algorithm

Hamsi is one of 14 remaining candidates in NIST's Hash Competition for the future hash standard SHA3 and Hamsi-256 is one of four kinds of Hamsi. In this paper we present a genetic algorithm to search near collisions for the compress function of Hamsi-256 , give a near collision on (256 − 20) bits and a near collision on (256 − 21) bits with four differences in the chaining value, and obtain a ...

متن کامل

High-Speed Hardware Implementations of BLAKE, Blue Midnight Wish, CubeHash, ECHO, Fugue, Gröstl, Hamsi, JH, Keccak, Luffa, Shabal, SHAvite-3, SIMD, and Skein

In this paper we describe our high-speed hardware implementations of the 14 candidates of the second evaluation round of the SHA-3 hash function competition. We synthesized all implementations using a uniform tool chain, standard-cell library, target technology, and optimization heuristic. This work provides the fairest comparison of all second-round candidates to date.

متن کامل

Collision Attack on the Hamsi-256 Compression Function

Hamsi-256 is a cryptographic hash functions submitted by Küçük to the NIST SHA-3 competition in 2008. It was selected by NIST as one of the 14 round 2 candidates in 2009. Even though Hamsi-256 did not make it to the final round in 2010 it is still an interesting target for cryptanalysts. Since Hamsi-256 has been proposed, it received a great deal of cryptanalysis. Besides the second-preimage at...

متن کامل

New Pseudo-Near-Collision Attack on Reduced-Round of Hamsi-256

Hamsi-256 is designed by Özgül Kücük and it has been a candidate Hash function for the second round of SHA-3. The compression function of Hamsi-256 maps a 256-bit chaining value and a 32-bit message to a new 256-bit chaining value. As hashing a message, Hamsi-256 operates 3-round except for the last message it operates 6-round. In this paper, we will give the pseudo-near-collision for 5-round H...

متن کامل

An Improved Algebraic Attack on Hamsi-256

Hamsi is one of the 14 second-stage candidates in NIST’s SHA-3 competition. The only previous attack on this hash function was a very marginal attack on its 256-bit version published by Thomas Fuhr at Asiacrypt 2010, which is better than generic attacks only for very short messages of fewer than 100 32-bit blocks, and is only 26 times faster than a straightforward exhaustive search attack. In t...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2009