【24h】

Rebound Attack on the Full LANE Compression Function

机译:对全车道压缩功能的反弹攻击

获取原文

摘要

In this work, we apply the rebound attack to the AES based SHA-3 candidate LANE. The hash function LANE uses a permutation based compression function, consisting of a linear message expansion and 6 parallel lanes. In the rebound attack on LANE, we apply several new techniques to construct a collision for the full compression function of LANE-256 and LANE-512. Using a relatively sparse truncated differential path, we are able to solve for a valid message expansion and colliding lanes independently. Additionally, we are able to apply the inbound phase more than once by exploiting the degrees of freedom in the parallel AES states. This allows us to construct semi-free-start collisions for full LANE-256 with 2~(96) compression function evaluations and 288 memory, and for full LANE-512 with 2~(224) compression function evaluations and 2~(128) memory.
机译:在这项工作中,我们将反弹攻击应用于基于AES的SHA-3候选车道。散列函数车道使用基于置换的压缩功能,包括线性消息扩展和6平行泳道。在对车道的反弹攻击中,我们应用了几种新技术来构造Lane-256和Lane-512的全压缩功能的碰撞。使用相对稀疏的截断差分路径,我们能够独立解决有效的消息扩展和碰撞车道。此外,我们能够通过利用并行AES状态的自由度来应用入站相。这允许我们为全车道-256构建半自由启动冲突,具有2〜(96)个压缩功能评估和288个内存,以及2〜(224)压缩功能评估和2〜(128)的全车道-512记忆。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号