[Cryptography] Name for a specific type of preimage resistance

Viktor Dukhovni cryptography at dukhovni.org
Tue Dec 13 22:13:43 EST 2022


On Tue, Dec 13, 2022 at 10:32:34AM +0000, Michael Kjörling wrote:

> Why? Because the size of the input space is effectively unbounded,
> whereas the size of the output space is bounded.

Indeed, my (e/e-1) random function preimage estimate is only for
endomorphisms.  Once the inputs can be much longer than the output,
we clearly expect a large number of preimages.  So never mind...

-- 
    Viktor.


More information about the cryptography mailing list