首页> 外文会议>Annual International Cryptology Conference >Higher-Order Differential Meet-in-the-middle Preimage Attacks on SHA-1 and BLAKE
【24h】

Higher-Order Differential Meet-in-the-middle Preimage Attacks on SHA-1 and BLAKE

机译:SHA-1和Blake上的高阶差分见面攻击中的中间攻击

获取原文

摘要

At CRYPTO 2012, Knellwolf and Khovratovich presented a differential formulation of advanced meet-in-the-middle techniques for preimage attacks on hash functions. They demonstrated the usefulness of their approach by significantly improving the previously best known attacks on SHA-1 from CRYPTO 2009, increasing the number of attacked rounds from a 48-round one-block pseudo-preimage without padding and a 48-round two-block preimage without padding to a 57-round one-block preimage without padding and a 57-round two-block preimage with padding, out of 80 rounds for the full function. In this work, we exploit further the differential view of meet-in-the-middle techniques and generalize it to higher-order differentials. Despite being an important technique dating from the mid-90's, this is the first time higher-order differentials have been applied to meet-in-the-middle preimages. We show that doing so may lead to significant improvements to preimage attacks on hash functions with a simple linear message expansion. We extend the number of attacked rounds on SHA-1 to give a 62-round one-block preimage without padding, a 56-round one-block preimage with padding, and a 62-round two-block preimage with padding. We also apply our framework to the more recent SHA-3 finalist BLAKE and its newer variant BLAKE2, and give an attack for a 2.75-round preimage with padding, and a 7.5-round pseudo-preimage on the compression function.
机译:在Crypto 2012年,Knellwolf和Khovratovich提出了一种差异的制定,用于散列攻击的先进态度的中间举行技术。他们通过显着改善了2009年Crypto的Sha-1的先前最佳的已知攻击来证明了他们的方法的有用性,从未填充了48圈的一块伪预报的攻击回合的数量,没有填充的48次在没有填充的情况下,无需填充到57圆形的单块纸张,而无需填充,50次与填充的57轮,为全函数为全功能。在这项工作中,我们进一步利用了中间技术的差异视图,并将其概括为高阶差异。尽管是从90年代中期进行的重要技术,但这是第一次高阶差异已经应用于与中间的次数相遇。我们表明这样做可能会导致具有简单线性消息扩展的哈希函数的预测攻击的重大改进。我们在SHA-1上延长了攻击轮的数量,提供了62轮的一块预测,无需填充,带有填充的56轮一块预测,以及带填充的62轮两块双块预测。我们还将框架应用于最近的SHA-3入围者制版及其较新的变体Blake2,并攻击2.75圆形的填充剂,压缩功能的7.5轮伪偏见。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号