Constructing a Set of Weak Values for Full-round MD4 Hash Function.

MIPRO(2020)

引用 2|浏览3
暂无评分
摘要
In this paper we describe the construction of a set of full-round MD4 compression function values, which are weak against the preimage attack of a special kind. The cardinality estimation for this set, obtained by using an effective probabilistic algorithm, is close to 232. According to this, the fraction of weak outputs in the set of all outputs of the MD4 compression function is about $2^{-96}$. Thus, the probability to obtain an easyinvertible output by choosing a random input is significantly higher than $2^{-128}$. These results demonstrate that the full-round MD4 compression function does not have the properties of a random oracle.
更多
查看译文
关键词
weak values,full-round
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要