How Risky is the Random-Oracle Model? Gaëtan Leurent and Phong NguynuFllv reisnoo &France&Aug. 19, 2009n http://eprint.iacr.org/2008/441
SummaryThe Random-Oracle Model (ROM)Random-Oracle InstantiationsRobustness of ROM Signatures with respect to Hash Function Defects
ACM CCS ’93The Random-Oracle Model
Hash FunctionsMany schemes or protocols use public hash functions: not easy to prove strong security properties.Usual hash functions: {0,1}*{0,1} hsaHfunctionMD5n821SHA-1061SHA-2 and SHA-3224, 256, 384, 512n