
272 Cryptography with Open-Source Software
and use an auxiliary function called a compression function f which takes
as input two blocks, one of q bits and another of n bits, and produces as
output an n-bit block. This construction also requires an n-bit initialization
vector IV, and the message m will have to be split into k blocks of q bits
each. This may require padding the last block (for example, with zeros and a
binary representation of the size of the message) to bring it up to size. The
hash value is the value of the last iteration. This construction is illustrated in
Figure 1 1.3.
IV
m
1
m
2
m
k−1
m
k
HASH
f f f f
Padding
FIGURE 11.3: The Merkle–Damg˚