
<script type="text/javascript">
<!--
document.write('<div id="oa_widget"></div>');
document.write('<script type="text/javascript" src="https://www.openaire.eu/index.php?option=com_openaire&view=widget&format=raw&projectId=undefined&type=result"></script>');
-->
</script>At CRYPTO 2008 Stam [8] conjectured that if an $$m\!+\!s$$-bit to s-bit compression function F makes r calls to a primitive f of n-bit input, then a collision for F can be obtained with high probability using $$r2^{nr-m/r+1}$$ queries to f, which is sometimes less than the birthday bound. Steinberger [9] proved Stam's conjecture up to a constant multiplicative factor for most cases in which $$r = 1$$ and for certain other cases that reduce to the case $$r = 1$$. In this paper we prove the general case of Stam's conjecture also up to a constant multiplicative factor. Our result is qualitatively different from Steinberger's, moreover, as we show the following novel threshold phenomenon: that exponentially many more exactly, $$2^{s-2m-n/r+1}$$ collisions are obtained with high probability after $$O1r2^{nr-m/r+1}$$ queries. This in particular shows that threshold phenomena observed in practical compression functions such as JH are, in fact, unavoidable for compression functions with those parameters.
| citations This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 8 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Top 10% |
