RIPEMD with two-round compress function is not collision-free

被引:46
作者
Dobbertin, H
机构
[1] German Information Security Agency, D-53133 Bonn
关键词
dedicated hash functions; RIPEMD; MD4; RACE project; ISO/IEC; 10118-3;
D O I
10.1007/s001459900019
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In 1990 Rivest introduced the cryptographic hash function MD4. The compress function of MD4 has three rounds. After partial attacks against MD4 were found, the stronger mode RIPEMD was designed as a European proposal in 1992 (RACE project). Its compress function consists of two parallel lines of modified versions of MD4-compress. RIPEMD is currently being considered to became an international standard (ISO/IEC Draft 10118-3). However, in this paper an attack against RIPEMD is described, which leads to comparable results with the previously known attacks against MD4: The reduced versions of RIPEMD, where the first or the last round of the compress function is omitted, are not collision-free. Moreover, it turns out that the methods developed in this note can be applied to find collisions for the full MD4.
引用
收藏
页码:51 / 69
页数:19
相关论文
共 6 条
[1]  
Bosselaers A., 1995, LECT NOTES COMPUTER, V1007, P69
[2]  
DENBOER B, 1992, LECT NOTES COMPUT SC, V576, P194
[3]  
Dobbertin Hans, 1996, LECT NOTES COMPUTER, V1039, P53
[4]  
RIVEST R, 1992, MD 5 MESSAGE DIGEST
[5]  
Rivest Ronald., 1992, The MD4 message-digest algorithm
[6]  
Vaudenay S., 1994, FAST SOFTWARE ENCRYP, V1008, P286, DOI DOI 10.1007/3-540-60590-8_22