## Prashant PuniyaThe Random Oracle Methodology

@MISC{Coron_prashantpuniyathe,

author = {Jean-sebastien Coron and Yevgeniy Dodis and Cecile Malinaud},

title = {Prashant PuniyaThe Random Oracle Methodology},

year = {}

}

### Abstract

♦ “Paradigm for designing secure and efficient protocols ” (BR’93). ♦ Assume existence of a publicly accessible ideal random function and prove protocol security. ♦ Replace ideal random function by an actual “secure hash function ” (such as SHA-1) to deploy protocol. ♦ Hope that nothing breaks down! Is SHA-1 Really Random? ♦ Is SHA-1 obscure enough to successfully replace a random oracle? ♦ No. Practical hash functions usually iteratively apply a fixed length compression function to the input (called the Merkle Damgard construction). f f f

