Question: A company suggests the following hash function: Let p > = 3 be a large prime with respect to which the discrete logarithm problem is

A company suggests the following hash function: Let p >=3 be a large prime with respect to which the discrete logarithm problem is intractable in _p^*. Let g_1, g_2 in _p^* be two distinct generators of _p^*. Define H : _p-1\times _p-1_p^* as H(x_1, x_2)=(g_1^x_1 g_2^x_2) p The company claims that this hash function is collision-resistant. Prove that they are wrong. Namely, present an algorithm C that given any p, g_1, g_2 that satisfy the above conditions very easily (formally, in time polynomial in |p|) outputs two pairs (x_1, x_2),(x_1^', x_2^') such that: -(x_1, x_2) in _p-1\times _p-1,-(x_1^', x_2^') in _p-1\times _p-1, and - H(x_1, x_2)=H(x_1^', x_2^'), but -(x_1, x_2)!=(x_1^', x_2^'). Be sure to justify your answer. Hint: Recalling the formula for calculating the Legendre symbol may be useful.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!