Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

RIPEMD with two-round compress function is not collision-free

Hans DobbertinContact Information

(1)  German Information Security Agency, P.O. Box 20 03 63, D-53133 Bonn, Germany

Received: 27 March 1995  Revised: 14 October 1995  

Communicated by Ivan B. Damgård
Abstract  In 1990 Rivest introduced the cryptographic hash function MD4. The compress function of MD4 has three rounds. After partial attacks against MD4 were found, the stronger mode RIPEMD was designed as a European proposal in 1992 (RACE project). Its compress function consists of two parallel lines of modified versions of MD4-compress. RIPEMD is currently being considered to become an international standard (ISO/IEC Draft 10118-3). However, in this paper an attack against RIPEMD is described, which leads to comparable results with the previously known attacks against MD4: The reduced versions of RIPEMD, where the first or the last round of the compress function is omitted, are not collision-free. Moreover, it turns out that the methods developed in this note can be applied to find collisions for the full MD4.

Key words  Dedicated hash functions - RIPEMD - MD4 - RACE project - ISO/IEC 10118-3


Contact Information Hans Dobbertin
Email: dobbertin@skom.rhein.de
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this article
Export this article as RIS | Text
 
Referenced by
2 newer articles

  1. WANG, Gao-Li (2008) . Journal of Software 19(9)
    [CrossRef]
  2. Preneel, B. (1999) On the security of iterated message authentication codes. IEEE Transactions on Information Theory 45(1)
    [CrossRef]
Remote Address: 38.107.191.108 • Server: mpweb02
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)