首页> 外文会议>International conference on selected areas in cryptography >Improved Single-Key Distinguisher on HMAC-MD5 and Key Recovery Attacks on Sandwich-MAC-MD5
【24h】

Improved Single-Key Distinguisher on HMAC-MD5 and Key Recovery Attacks on Sandwich-MAC-MD5

机译:改进的HMAC-MD5单键识别器和Sandwich-MAC-MD5的密钥恢复攻击

获取原文

摘要

This paper presents key recovery attacks on Sandwich-MAC instantiating MD5, where Sandwich-MAC is an improved variant of HMAC and achieves the same provable security level and better performance especially for short messages. The increased interest in lightweight cryptography motivates us to analyze such a MAC scheme. We first improve a distinguishing-H attack on HMAC-MD5 proposed by Wang et al. We then propose key recovery attacks on Sandwich-MAC-MD5 by combining various techniques such as distinguishing-H for HMAC-MD5, Ⅳ Bridge for APOP, dBB-near-collisions for related-key NMAC-MD5, meet-in-the-middle attack etc. In particular, we generalize a previous key-recovery technique as a new tool exploiting a conditional key-dependent distribution. Our attack also improves the partial-key (K_1) recovery on MD5-MAC, and extends it to recover both K_1 and K_2.
机译:本文介绍了对Sandwich-MAC实例化MD5的关键恢复攻击,其中Sandwich-MAC是HMAC的改进版本,并实现了相同的可证明的安全级别和更好的性能,尤其是对于短消息。人们对轻量级密码学的兴趣日增,促使我们分析这种MAC方案。我们首先改善了Wang等人提出的针对HMAC-MD5的区分H攻击。然后,我们通过结合各种技术(例如,针对HMAC-MD5的区分H,针对APOP的Ⅳ桥,针对相关密钥NMAC-MD5的dBB近碰撞,相遇等)对Sandwich-MAC-MD5提出密钥恢复攻击。特别是,我们将以前的密钥恢复技术概括为一种利用条件密钥相关分布的新工具。我们的攻击还改善了MD5-MAC上的部分密钥(K_1)恢复,并将其扩展为同时恢复K_1和K_2。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号