3 ms·
Simple hash, 128-bit mixing function is just: mix(const int A) { const int B = A+1; ds[A] *= P; ds[A] = rot(ds[A], 23); ds
by fantastisch 6y ago
Simple hash, 128-bit mixing function is just:
mix(const int A)
{
const int B = A+1;
ds[A] *= P;
ds[A] = rot(ds[A], 23);
ds[A] *= Q;
ds[B] ^= ds[A];
ds[B] *= P;
ds[B] = rot(ds[B], 23);
ds[B] *= Q;
}
with P and Q prime.
- gliptic 6y agoPlease modify this: "The standard digest is 64-bits, but you can modify it to take 128-bits if you want a cryptographically secure hash." Just because it's 128-bit doesn't make it cryptographically secure.
- fantastisch 6y agoCan you break 128-bits? How should I say it?
- espadrine 6y agoHi Cris! First of all, I love to see new hash designs, it is great! The standard disclaimer is “please do not use this for cryptographic purposes,” placed at the top of the README. (I like to add a hint afterwards, like “If you need security, please use BLAKE3.”) Second, if you do want to make a version in the same family with cryptographic properties, a few things are expected: • Careful list of cryptographic claims (is it a PRF? a PRP? a compression function? is it collision resistant? with what probability of success?…) • A published paper with preliminary cryptanalysis. What is the average number of evaluations of the hash function for key recovery? How much probabilistic information of the state bits can be gained from the output? How much output leads to a state recovery? What is the worst statistical bias of the output from single-bit input changes? • Multiple rounds. The production hash should use at least one more round than is shown to be cryptanalytically safe; ideally twice. • I worry that multiplication, in particular 128-bit multiplication, is subject to timing attacks. It is uncommon to see it used in cryptographic hashes. Disclaimer: I am not a cryptographer by trade, so this advice is insufficient.
- fantastisch 6y agoIf your think multiplication is weird, you should check out my floppsy https://github.com/dosyago/floppsy https://github.com/dosyago/floppsy It uses division and floating point! You're welcome to try your hand at cryptanalysis. I think a lot of the statical properties are measured in the SMHasher results. Thank you, Thaddée :)