[Cryptography] Name for a specific type of preimage resistance
Viktor Dukhovni
cryptography at dukhovni.org
Tue Dec 13 22:13:43 EST 2022
On Tue, Dec 13, 2022 at 10:32:34AM +0000, Michael Kjörling wrote:
> Why? Because the size of the input space is effectively unbounded,
> whereas the size of the output space is bounded.
Indeed, my (e/e-1) random function preimage estimate is only for
endomorphisms. Once the inputs can be much longer than the output,
we clearly expect a large number of preimages. So never mind...
--
Viktor.
More information about the cryptography
mailing list