æ¬è¨äºã¯ æå·å¦ä¸äººã¢ããã³ãã«ã¬ã³ã㼠第6æ¥ç®(ç¸å½)ã®è¨äºã§ãã
ä»åã®å 容ã¯SHA-1ãç¾å®çã«çªç ´ãããã¨ããSHAtteredã®è«æããã¨ã«ãSHA-0/SHA-1ã¸ã®æ»æãããã«ãã¦è¡ããããã®æ¦è¦ã¨ãä½ãã¾ããã£ããããè¦ã¦ããã¾ãã
ç°¡åãªSHA-1ã®ä»çµã¿
SHA-1, SHA-2ã¯Merkle-DamgÃ¥rdæ§é ã¨ãããåºå®ã®åæåãã¯ãã«ã¨ã¡ãã»ã¼ã¸ã«å¯¾ãã¦å§ç¸®é¢æ°ãç¹°ãè¿ãé©ç¨ãããã¨ã§æçµçãªåºåãå¾ãæ¹å¼ãåãã¾ããSHA-0/1/2ã¯ãããããã®å§ç¸®é¢æ°ãç°ãªãããæ§è³ªãç°ãªã£ã¦ãã¾ããSHA-0ã®å§ç¸®é¢æ°ãèå¼±ã§ãããã¨ãå¤æãããããSHA-1ã¯ãã®SHA-0ã®å§ç¸®é¢æ°ã«bitwise rotationã1åå ãã£ã¦ç¾å¨ã®å½¢ã«ãªã£ã¦ãã¾ããSHA-2ã¯ãããã¨ã¯å ¨ãç°ãªãå§ç¸®é¢æ°ã使ç¨ãã¦ãã¾ãã
SHA-0ã«å¯¾ããæ»æã¨SHA-1ã¸ã®å¿ç¨
SHA-0ã«å¯¾ããæ»æã§ãæçµçãªSHA-1ã®æ»æã«å½±é¿ãç¹ã«å¤§ããã£ããã®ã¨ãã¦ãDifferential Collisions in SHA-0 (Chabaud and Joux, 1998)ã§ç´¹ä»ããã¦ããå·®å解èªæ³(Differential cryptanalysis) ã«ããè¡çªæ»æãããã¾ãã大ã¾ãã«ããã¨ãå ¥åã®ç¹å®1ãã¤ããå¤ããã¨ãã«å é¨ã®ç¶æ ãããï¼å§ç¸®é¢æ°ã«ãããããå¤ã®çæ¹ï¼ãã©ã®ããã«å¤åãããã追跡ããããã®ãã¹ãæ§ç¯å¯è½ã§ãããã¨ãè¦ã¤ãããã¨ãããã®ã§ããSHA-1ã¯ããã解決ããããºã§ããããå®ã¯ãã®åé¡ã¯ç¹°ãè¿ãç¾ãããã¨ã¨ãªããçµæã¨ãã¦å·®å解èªã«å¼±ãå§ç¸®é¢æ°ã使ã£ããã¨ãSHA-1ã®è¡çªãè¦ã¤ãããããåå ã®ä¸ã¤ã«ãªã£ãã¨ãããã§ããããã¾ãããã®è«æã§ã¯ãlocal collisionã¨ããå é¨ç¶æ ã6ãµã¤ã¯ã«ã§åãå¤ã«æ»ããã¨ããæ§è³ªãæããã«ãã¦ãã¾ãã
SHAtteredè«æã®4ç« ã®å³
ããããèæ¯ãæããä¸ã§è¦ãã¨4ç« ã®overviewã®å³ã®æå³ãåãããããªãã¾ãã
- SHA-1ã®å§ç¸®é¢æ°ã¯å é¨ã§16ã©ã¦ã³ããã¨ã«ç°ãªãé¢æ°ãé©ç¨ãããããæåã®16ã©ã¦ã³ãã®å é¨ç¶æ ã¾ã§ã¯æä½ãããããããæ®ãã®64ã©ã¦ã³ãã¯æä½ãå°é£ã§ãããã¨ããã®ã(1)ã§ç¤ºãã¦ããé¨åã
- æçµçãªç®çã¨ãã¦ã¯ã1ãããã¯ç®ã§çã¿åºãããããã®å·®å(+)ã2ãããã¯ç®ã§æã¡æ¶ãã¦(-)ã¼ãã«ãããã¨ãããã¨ãç®æãã¦ãã(2)
- ããã£ã¨æ¸ãã¦ãããã©æ¬æ¥ã©ã³ãã ã«è¦ãããããªåºåãåºãããºã®ãã®ã«å¯¾ãã¦ãããããã¨ãã£ã¦ãã®ã ããæããããã¨ã§ã
- ãã®ããã«ã"differential path"ã¨ãããå é¨ç¶æ ã¨ã¡ãã»ã¼ã¸ã®å·®åãã©ã®ããã«æ®ãã®ã¹ãããã§ä¼æ¬ãããã®ãã¹ããé½åã®ããããã«ãæ§ç¯ãã"Non-Linear path"ãä½æããå¿ è¦ããã(3)
- æçµçã«ã¯near-collision block pair(4A, 4B)ã®å½¢ã§è§£ãå¾ãããã
ã¡ãã£ã¨æ¶åä¸è¯æ°å³ã§ãããããªã¨ããã§ãæ¹ãã¦èªã¿è¾¼ãããæ¸ãç´ãããã
éå»è¨äºã®å®£ä¼ã§ããSHA-2ã®freestart collision attackã¨ãããå§ç¸®é¢æ°ã®ä¸åç¹ãè¦ã¤ãã£ããã¨ãã話ã«ã¤ãã¦è¨äºãæ¸ãã¦ã¾ãã
次åã¯SHA-2ã®è©±ãã£é£ã°ãã¦SHA-3(Keccak)ãªã©ã®Merkle-DamgÃ¥rdã§ãªãããã·ã¥ã®è©±ã®äºå®ã§ããããããããä»æ¥ä¸ã