Original title:
Analýza pseudonáhodnosti autentizačních funkcí typu HMAC
Translated title:
Analysis of the pseudo-randomness of HMAC-type authentication functions
Authors:
Ďuroň, Peter ; Zeman, Václav (referee) ; Burda, Karel (advisor) Document type: Bachelor's theses
Year:
2026
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[cze][eng]
Táto bakalárska práca sa zaoberá experimentálnou analýzou štatistických vlastností autentizačných funkcií typu HMAC so zameraním na ich pseudonáhodnosť. Hlavným cieľom bolo navrhnúť a implementovať softvérový nástroj, ktorý umožňuje testovanie vybraných hašovacích algoritmov — MD5, SHA-256 a SHA3-256 — v modifikovanom režime HMAC. V rámci riešenia bolo navrhnutých päť metód mapovania vstupných a výstupných premenných, ktoré slúžia na skúmanie vplyvu distribúcie bitov na výslednú uniformitu výstupov. Analýza prebiehala prostredníctvom metódy zväzkov a Pearsonovho testu dobrej zhody (2), pričom sa sledovala miera zhody nameraných početností s teoretickým bino- mickým rozdelením. Výsledky analýzy preukázali, že kým algoritmus SHA-256 vykazuje najvyššiu mieru stability naprieč rôznymi konfiguráciami, starší algoritmus MD5 a moderný štandard SHA-3 vykazujú pri špecifických typoch mapovania lokálne štatistické anomálie. Experimentálne sa potvrdilo, že najrobustnejšiu metódu predstavuje mapovanie založené na bitovej expanzii a kumulatívnej operácii XOR, ktoré efektívne eliminuje vplyv statických výplní na výslednú pseudonáhodnosť.
This bachelor thesis examines the experimental analysis of the statistical properties of HMAC-type authentication functions with a focus on their pseudo-randomness. The primary objective involved the design and implementation of a software tool capable of testing selected hash algorithms—MD5, SHA-256, and SHA3-256—within a modified HMAC framework. Five mapping methods for input and output variables were developed to investigate the impact of bit distribution on the resulting uniformity of the outputs. The analysis utilized the bundle method and Pearson’s chi-squared (2) goodness-of-fit test to monitor the alignment of measured frequencies with the theoretical binomial distribution. The results demonstrate that while SHA-256 exhibits high stability across various configurations, MD5 and SHA3-256 show local statistical anomalies under specific mapping types. Experimentally, the mapping method based on bit expansion and cumulative XOR (M5) proved to be the most robust, effectively eliminating the influence of static padding on the resulting pseudo-randomness. The developed software provides an efficient platform for evaluating authentication functions and identifying potential vulnerabilities in their statistical distribution.
Keywords:
bundle analysis.; goodness-of-fit test; hash function; HMAC; mapping; MD5; pseudo-randomness; SHA-256; SHA-3; statistical testing; hašovacia funkcia; HMAC; mapovanie.; MD5; pseudonáhodnosť; SHA-256; SHA-3; test dobrej zhody; štatistické testovanie
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258302