## Herding hash functions and the Nostradamus attack (2006)

Venue: of Lecture Notes in Computer Science

Citations: 25 - 6 self

### BibTeX

@INPROCEEDINGS{Kelsey06herdinghash,

author = {John Kelsey and Tadayoshi Kohno},

title = {Herding hash functions and the Nostradamus attack},

booktitle = {of Lecture Notes in Computer Science},

year = {2006},

pages = {183--200},

publisher = {Springer}

}

### Years of Citing Articles

### Abstract

Abstract. In this paper, we develop a new attack on Damg˚ard-Merkle hash functions, called the herding attack, in which an attacker who can find many collisions on the hash function by brute force can first provide the hash of a message, and later “herd ” any given starting part of a message to that hash value by the choice of an appropriate suffix. We focus on a property which hash functions should have–Chosen Target Forced Prefix (CTFP) preimage resistance–and show the distinction between Damg˚ard-Merkle construction hashes and random oracles with respect to this property. We describe a number of ways that violation of this property can be used in arguably practical attacks on real-world applications of hash functions. An important lesson from these results is that hash functions susceptible to collision-finding attacks, especially brute-force collision-finding attacks, cannot in general be used to prove knowledge of a secret value. 1

