1

Some PQC schemes don't require collision resistance for their hash functions, thus using a hash function faster than the SHA series that only considers the pre-image and secondary pre-image resistance would speed up these schemes.

Is there such a standard for hash functions that 1st and 2nd preimage resistant but not necessarily collision resistant?

kelalaka
  • 48,443
  • 11
  • 116
  • 196
user86443
  • 41
  • 1

0 Answers0