ISO/IEC 10118-4:1998
Information technology — Security techniques — Hash-functions — Part 4: Hash-functions using modular arithmetic
Information technology — Security techniques — Hash-functions — Part 4: Hash-functions using modular arithmetic
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 23
- Дата публикации:
- 20 декабря 1998 г.
- Издание:
- ISO/IEC IS 10118 edition 1 version 1
- ICS:
- 35.030
This part of ISO/IEC 10118 specifies two hash-functions which make use of modular arithmetic. These hash-functions, which are believed to be collision-resistant, compress messages of arbitrary but limited length to a hash-code whose length is determined by the length of the prime number used in the reduction-function defined in 7.3. Thus, the hash-code is easily scaled to the input length of any mechanism (e.g., signature algorithm, identification scheme). The hash-functions specified in this part of ISO/IEC 10118, known as MASH-1 and MASH-2 (Modular Arithmetic Secure Hash) are particularly suitable for environments in which implementations of modular arithmetic of sufficient length are already available. The two hash-functions differ only in the exponent used in the round-function.
Abstract
Overview
ISO/IEC 10118-4:1998 specifies two modular-arithmetic based hash-functions - MASH-1 and MASH-2 (Modular Arithmetic Secure Hash). These functions compress messages of arbitrary but limited length into a fixed-length hash-code. The output length is determined by the length of the prime p used in the standard’s reduction-function, allowing the hash size to be scaled to match the input requirements of other mechanisms (for example, signature algorithms or identification schemes). The algorithms are designed to be collision-resistant under standard number-theoretic assumptions.
Key topics and technical requirements
- Modular arithmetic round-function: A round-function φ combines expanded data blocks with previous outputs using modular operations modulo a composite modulus N.
- Two variants:
- MASH-1 uses exponent e = 2 in the round-function.
- MASH-2 uses exponent e = 257; otherwise the two differ only by exponent.
- Reduction-function (RED): After iterative rounds, a reduction modulo a prime p produces the final hash-code of length determined by p.
- Data preparation: The hashing procedure includes padding, appending the original length, splitting into half-blocks, and expansion (inserting fixed half-bytes), as specified in the standard.
- Security constraints:
- The modulus N must be a composite integer (product of two primes) chosen so that factoring N is computationally infeasible.
- The factors of N should remain secret (trusted generation or secure multiparty methods).
- The reduction prime p must not divide N, its length is at most half the bit-length of N, and its top three bits should be ones to avoid unbalanced reductions.
- Initialization: The initializing value IV is all-zero string of the block length Lφ.
- Identifiers: Hash-function identifiers are defined (MASH-1 = 0x41, MASH-2 = 0x42).
Applications and who would use it
- Cryptographers and security engineers who need hash-functions compatible with existing modular-arithmetic infrastructure (e.g., systems already supporting large-modulus arithmetic).
- Implementers of digital signature schemes and identification protocols where the hash length must match modulus- or key-dependent input sizes.
- Standards bodies and evaluators assessing alternative hash constructions based on number-theoretic assumptions.
- Suited for environments where modular-root and factoring hardness are acceptable security bases and where efficient modular-arithmetic implementations are available.
Related standards
- ISO/IEC 10118-1: General definitions and conventions for hash-functions.
- Other parts of ISO/IEC 10118: Part 2 (block-cipher based) and Part 3 (dedicated hash-functions) for alternative hash-function families.
Keywords: ISO/IEC 10118-4:1998, hash-functions, modular arithmetic, MASH-1, MASH-2, collision-resistant, modulus N, prime p, reduction-function, round-function, hash-code.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 10118-4:1998
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 10118-1:2016+A1:2021
ДействующийInformation technology. Security techniques. Hash-functions. General.
ISO/IEC 10118-3:2018
ДействующийIT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
Overview ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…