MD4 is Not One-Way

被引:0
|
作者
Leurent, Gaetan [1 ]
机构
[1] Ecole Normale Super, Dept Informat, F-75230 Paris 05, France
来源
FAST SOFTWARE ENCRYPTION | 2008年 / 5086卷
关键词
MD4; hash function; cryptanalysis; preimage; one-way;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
MD4 is a hash function introduced by Rivest in 1990. It is still used in some contexts, and the most commonly used hash functions (MD5, SHA-1, SHA-2) are based on the design principles of MD4. MD4 has been extensively studied and very efficient collision attacks are known, but it is still believed to be a one-way function. In this paper we show a partial pseudo-preimage attack on the compression function of MD4, using some ideas from previous cryptanalysis of MD4. We can choose 64 bits of the output for the cost of 2(32) compression function computations (the remaining bits are randomly chosen by the preimage algorithm). This gives a preimage attack on the compression function of MD4 with complexity 2(96), and we extend it to an attack on the full MD4 with complexity 2(102). As far as we know this is the first preimage attack on a member of the MD4 family.
引用
收藏
页码:412 / 428
页数:17
相关论文
共 50 条
  • [1] The first two rounds of MD4 are not one-way Extended abstract
    Dobbertin, H
    FAST SOFTWARE ENCRYPTION, 1998, 1372 : 284 - 292
  • [2] Cryptanalysis of MD4
    Dobbertin, H
    JOURNAL OF CRYPTOLOGY, 1998, 11 (04) : 253 - 271
  • [3] Cryptanalysis of MD4
    Hans Dobbertin
    Journal of Cryptology, 1998, 11 : 253 - 271
  • [4] Improved preimage attack on one-block MD4
    Zhong, Jinmin
    Lai, Xuejia
    JOURNAL OF SYSTEMS AND SOFTWARE, 2012, 85 (04) : 981 - 994
  • [5] The MD2 hash function is not one-way
    Muller, F
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2004, PROCEEDINGS, 2004, 3329 : 214 - 229
  • [6] MD4算法分析
    黎琳
    山东大学学报(理学版), 2007, (04) : 1 - 5
  • [7] THE MD4 MESSAGE DIGEST ALGORITHM
    RIVEST, RL
    LECTURE NOTES IN COMPUTER SCIENCE, 1991, 537 : 303 - 311
  • [8] THE MD4 MESSAGE DIGEST ALGORITHM
    KALISKI, BS
    LECTURE NOTES IN COMPUTER SCIENCE, 1991, 473 : 492 - 492
  • [9] Searching for differential paths in MD4
    Schlaffer, Martin
    Oswald, Elisabeth
    FAST SOFTWARE ENCRYPTION, 2006, 4047 : 242 - 261
  • [10] New message difference for MD4
    Sasaki, Yu
    Wang, Lei
    Ohta, Kazuo
    Kunihiro, Noboru
    FAST SOFTWARE ENCRYPTION, 2007, 4593 : 329 - +