Preimages for Zémor's Cayley hash function

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: McKemmie, Eilidh, Srivastava, Amol
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908665881034752
author McKemmie, Eilidh
Srivastava, Amol
author_facet McKemmie, Eilidh
Srivastava, Amol
contents In 1991, Zémor proposed a hash function which provides data security using the difficulty of writing a given matrix as a product of generator matrices. Tillich and Zémor subsequently provided an algorithm finding short collisions for this hash function. We extend this collision attack to a stronger preimage attack, under the assumption that we can factor large integers efficiently. The Euclidean algorithm will factor a $2\times 2$ matrix with non-negative integer entries and determinant $1$. This factorization is short if the matrix entries are all roughly the same size. Therefore, to factor a matrix we need only find an integer matrix with the listed properties which is congruent to the target matrix modulo $p$; finding such an integer matrix is equivalent to solving a Diophantine equation. We give an algorithm to solve this equation.
format Preprint
id arxiv_https___arxiv_org_abs_2511_15842
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Preimages for Zémor's Cayley hash function
McKemmie, Eilidh
Srivastava, Amol
Group Theory
20G40 20G40, 11T71
In 1991, Zémor proposed a hash function which provides data security using the difficulty of writing a given matrix as a product of generator matrices. Tillich and Zémor subsequently provided an algorithm finding short collisions for this hash function. We extend this collision attack to a stronger preimage attack, under the assumption that we can factor large integers efficiently. The Euclidean algorithm will factor a $2\times 2$ matrix with non-negative integer entries and determinant $1$. This factorization is short if the matrix entries are all roughly the same size. Therefore, to factor a matrix we need only find an integer matrix with the listed properties which is congruent to the target matrix modulo $p$; finding such an integer matrix is equivalent to solving a Diophantine equation. We give an algorithm to solve this equation.
title Preimages for Zémor's Cayley hash function
topic Group Theory
20G40 20G40, 11T71
url https://arxiv.org/abs/2511.15842