In this paper, we evaluate the security of the message authentication code SipHash against forgery attacks. Existing evaluations focused on internal collisions for SipHash-1- \( x \) and SipHash-2- \( x \) , where the internal compression rounds are reduced to one and two rounds out of four, respectively, and the finalization rounds are set to an arbitrary number. In this paper, we extend this analysis by expanding the search space to provide a more comprehensive evaluation of SipHash-1- \( x \) and SipHash-2- \( x \) , and we also evaluate internal collisions for SipHash-3- \( x \) and SipHash-4- \( x \) by using a method involving SAT solvers. Besides, we perform the first security evaluation of forgery attacks exploiting tag collisions during the finalization process. As a result, we update existing bounds on internal collisions of SipHash-1- \( x \) and SipHash-2- \( x \) and derive first bounds of SipHash-3- \( x \) and SipHash-4- \( x \) . Furthermore, we demonstrate that forgery attacks using tag collisions are feasible for SipHash-1-1, SipHash-1-0, and SipHash-2-0. These findings represent the first forgery attacks against SipHash with reduced rounds. Finally, we demonstrate that modifying rotation parameters in the round function achieves a substantial improvement in security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Forgery Attacks on SipHash

  • Kosuke Sasaki,
  • Rikuto Kurahara,
  • Kosei Sakamoto,
  • Takanori Isobe

摘要

In this paper, we evaluate the security of the message authentication code SipHash against forgery attacks. Existing evaluations focused on internal collisions for SipHash-1- \( x \) and SipHash-2- \( x \) , where the internal compression rounds are reduced to one and two rounds out of four, respectively, and the finalization rounds are set to an arbitrary number. In this paper, we extend this analysis by expanding the search space to provide a more comprehensive evaluation of SipHash-1- \( x \) and SipHash-2- \( x \) , and we also evaluate internal collisions for SipHash-3- \( x \) and SipHash-4- \( x \) by using a method involving SAT solvers. Besides, we perform the first security evaluation of forgery attacks exploiting tag collisions during the finalization process. As a result, we update existing bounds on internal collisions of SipHash-1- \( x \) and SipHash-2- \( x \) and derive first bounds of SipHash-3- \( x \) and SipHash-4- \( x \) . Furthermore, we demonstrate that forgery attacks using tag collisions are feasible for SipHash-1-1, SipHash-1-0, and SipHash-2-0. These findings represent the first forgery attacks against SipHash with reduced rounds. Finally, we demonstrate that modifying rotation parameters in the round function achieves a substantial improvement in security.