11 citations found. Retrieving documents...
T. Johansson, G. Kabatianskii, and B. Smeets, "On the relation between A-codes and codes correcting independent errors," Proc. Eurocrypt'93, LNCS 765, Springer-Verlag, 1994, pp. 1--11.

 Home/Search   Document Not in Database   Summary   Related Articles   Check  

This paper is cited in the following contexts:
Cryptanalysis of the Gemmell and Naor Multiround Authentication.. - Gehrmann (1994)   (1 citation)  (Correct)

.... of mfivcrsal hashing for authentication codes (A codes) without secrecy, so called Cartesian A codes, was first described in [2] The general authentication problem was formulated in information theoretic terms by Simmons [3] Many constructions and bounds have been derived for Cartesian A codes [4] [5] 61 , 7] and it. is possible to construct such codes, which re close to the theoretical bounds. Itowever all these constructions only deal with single transmission authentication. Gemmell and Naor [9] proposed a multiple round authentication protocol. Let , denote the message length, ....

....with single transmission authentication. Gemmell and Naor [9] proposed a multiple round authentication protocol. Let , denote the message length, H(I, the key entropy and P the probability for a successthl substitution attack. For single round Cartesian authentication codes it, was shown that [4] H(K) log(r0 21og( log log( 1) The Gemmell and Naor k round protocol obtains: H(Jx ) log(k 1) n) 5 1og( s ) 2) and Gcmmell and Naor proved the existence of a k round protocol such that H(I, 1og; 1)0 ) 2log( p. 3) This work was supported by the TFR grant 222 92 662. 122 ....

T. Johansson, G. Kabatanskii, B. Smeets, "On the relation between A-codes and codes correcting independent errors", Proceedin,qs of Eurocr.qpt 'g.q, 1993, pp. 1-11.


Universal Hashing and Geometric Codes - Bierbrauer (1997)   (1 citation)  (Correct)

....some more basic properties of the function m: m(#, v , M ) m(#, v, M) This is Stinson s Cartesian product construction (see [16] In the case of linear codes we may describe this as extension of constants. Concatenation of codes yields m(# 1 # 2 ,v,M)#m(# 2 ,v,M 1 )m(# 1 , M 1 , M) In [12] the relation between ASU 2 classes and AU 2 classes of hash functions is studied. We note the following main results in our present notation: If q is a prime power, then . m(#, q, q(q 1)k q) m A (#, q, k) m A (#, q, q 1)k 1)#qmA (#, q, k) The 2 dimensional Reed Solomon code shows ....

T. Johansson, G. Kabatianskii and B. Smeets, On the relation between A-codes and codes correcting independent errors, Proceedings Eurocrypt 93, pp. 1--11.


Crypto Topics and Applications I - Seberry, Charnes, Pieprzyk..   (Correct)

....cartesian A codes, is the size of the tag space for a fixed size of source space and probability of success in substitution. Stinson [72] shows that, for perfect protection against substitution, the size of key space grows linearly with the size of the source. Johansson, Kabatianskii and Smeets [37] show that: if P 1 P 0 , A codes with an exponential (in E) number of source states can be obtained. 2.5 A codes and E codes An error correcting code provides protection against random channel error The study of error correcting codes was motivated by Shannon s channel capacity theorem and has ....

....the most likely alterations as closely about the original code as possible and the other (authentication theory) with spreading the optimal (to the opponent) alterations as uniformly as possible over M. The relation between E codes and A codes is explored in the work of Johansson et al. [37], who show that it is possible to construct E codes from A codes and vice versa. Their work uses a worst case analysis approach in analyzing the security of A codes. That is, in the case of substitution attack, they consider the best chance of success an enemy has when it intercepts all possible ....

[Article contains additional citation context not shown here]

T. Johansson, G. Kabatianskii, and B. Smeets. On the relation between A-codes and codes correcting independent errors. Proc. Eurocrypt'93, LNCS Vol. 765, Springer-Verlag, Berlin, 1994, pp. 1-11. 32


Bounds and Constructions for Multireceiver Authentication Codes - Safavi-Naini, Wang   (Correct)

....of KO bounds to MRA systems that are not perfect. Finally, we present two new constructions for MRA codes using linear errorcorrecting codes (E codes) The constructions are particularly important because they give MRA codes from arbitrary E codes and can be seen as extension of Johansson et al. [9] work relating E codes and A codes. This established link allows us to apply bounds and constructions from the well developed discipline of E codes to the construction of new MRA systems. Using maximum distance separable codes in the first construction, and special values for parameters in the ....

T. Johansson, G. Kabatianskii and B. Smeets, On the relation between A-codes and codes correcting independent errors. In "Advances in Cryptology -- Eurocrypt '93", Lecture Notes in Computer Science 765 (1993), 1-11.


Universal Hashing and Geometric Codes - Bierbrauer (1994)   (1 citation)  (Correct)

....function m : m(ffl; v i ; M i ) m(ffl; v; M) This is Stinson s Cartesian product construction (see [17] In the case of linear codes we may describe this as extension of constants. Concatenation of codes yields m(ffl 1 ffl 2 ; v; M) m(ffl 2 ; v; M 1 ) Delta m(ffl 1 ; M 1 ; M) In [13] the relation between ASU 2 Gammaclasses and AU 2 Gammaclasses of hash functions is studied. We note the following main results in our present notation: If q is a prime power, then 4 ffl m(ffl; q; q(q Gamma 1)k q) mA (ffl; q; k) ffl mA (ffl; q; q Gamma 1)k 1) q Delta mA (ffl; q; ....

T. Johansson, G. Kabatianskii, B. Smeets, On the relation between A-codes and codes correcting independent errors, Proceedings Eurocrypt'93,1-11.


MDx-MAC and Building Fast MACs from Hash Functions - Preneel, van Oorschot (1995)   (34 citations)  (Correct)

....relatively fast in software (about 40 slower than MD5) Its main disadvantage is that the result, being 32 bits, is considered unacceptably short for many applications. Recent research on authentication codes has resulted in very fast, scalable, and information theoretically secure constructions [16, 19, 28], which require relatively short keys. The disadvantage is that a different key must be used for every message. If this is not acceptable, one can generate the key using a cryptographically strong pseudo random string generator, but the resulting scheme is then (at most) computationally secure. ....

T. Johansson, G. Kabatianskii, B. Smeets, "On the relation between A-codes and codes correcting independent errors," Proc. Eurocrypt'93, LNCS 765, SpringerVerlag, 1994, pp. 1--11.


On the Connections Between Universal Hashing, Combinatorial.. - Stinson   (Correct)

....be preferred since they are smaller. It is also possible to use certain error correcting codes to construct ffl DeltaU hash families for various values of ffl. Here is a very useful construction, which is essentially the same as the q twisted construction of Johansson, Kabatianskii and Smeets [12, 13]. Theorem 4.7 If there exists an [N; k; D; q] code C with the property that e = 1; 1) 2 C, then there exists a (1 Gamma D N ) DeltaU (N ; q k Gamma1 ; q) hash family defined over F q . Proof. Let C 1 ; C q k Gamma1 be a set of representatives of the quotient space C=hei. ....

T. Johansson, G. Kabatianskii and B. Smeets, On the Relation Between A-Codes and Codes Correcting Independent Errors. In "Advances in Cryptology -- EUROCRYPT '93", T. Helleseth, ed., Lecture Notes in Computer Science 765 (1994), 1--11.


Bucket Hashing with a Small Key Size - Johansson (1997)   (7 citations)  Self-citation (Johansson)   (Correct)

....and can even be executed in parallel on many processors. The drawback of the bucket hashing approach is the long key that is used. The key size is approximately 3n log 2 N , which is huge. For n = 1024 and N = 100, this is already more than 20000 bits, whereas a theoretically good construction [6, 14] for the same ffl would require 76 key bits. Hence, the key bits in the bucket hashing construction must be generated by a pseudo random number generator. This might be time consuming and the hash families are no longer unconditionally secure. 4 Bucket hashing with a small key size The purpose ....

....key size The purpose of this section is to slightly modify some existing constructions of ffl AU 2 families of hash functions and then show that they can be implemented in a way that resembles the bucket hashing technique. The approach taken here is based on evaluation of polynomials similar to [6, 14]. The difference is essentially that we only consider polynomials over GF (2) whereas the previous approaches consider polynomials over a larger field. The following is a description of an ffl AU 2 family of hash functions. Let PD be the set of all polynomials over GF (2) without constant term ....

[Article contains additional citation context not shown here]

T. Johansson, G. Kabatianskii, B. Smeets, On the relation between A-codes and codes correcting independent errors, Lecture Notes in Computer Science, 765 (1994), 1--11 (EUROCRYPT'93).


Security Analysis of the Message Authenticator Algorithm.. - Preneel, Rijmen, van.. (1997)   (Correct)

No context found.

T. Johansson, G. Kabatianskii, and B. Smeets, "On the relation between A-codes and codes correcting independent errors," Proc. Eurocrypt'93, LNCS 765, Springer-Verlag, 1994, pp. 1--11.


Bucket Hashing and its Application to Fast Message Authentication - Rogaway (1995)   (39 citations)  (Correct)

No context found.

T. Johansson, G. Kabatianskii and B. Smeets, On the relation between A-codes and codes correcting independent errors. Advances in Cryptology - EUROCRYPT '93, Lecture Notes in Computer Science, vol. 765, Springer-Verlag, 1994, pp. 1-11.


Bucket Hashing and its Application to Fast Message Authentication - Rogaway (1997)   (39 citations)  (Correct)

No context found.

T. Johansson, G. Kabatianskii and B. Smeets, On the relation between A-codes and codes correcting independent errors. Advances in Cryptology -- EUROCRYPT '93, Lecture Notes in Computer Science, vol. 765, Springer-Verlag, 1994, pp. 1--11.

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC