On the Length of Hash-values for Digital Signature Schemes

  • Lim, Chae-Hoon (Dept. of Electrical Engineering, Pohang University of Science and Technology) ;
  • Lee, Pil-Joong- (Dept. of Electrical Engineering, Pohang University of Science and Technology)
  • Published : 1994.11.01

Abstract

In digital signature schemes derived from the zero-knowledge proof techniques, some authors often claims that the length of hash-values for their schemes could be as short as 64 or 72 bits for the security level of 2$^{-64}$ or 2$^{-72}$ . This letter shows that signature schemes with such short hash values cannot achieve the security levels as stated, due to the birthday attack by the signer.

Keywords