跳到主要导航 跳到搜索 跳到主要内容

Improved single-key distinguisher on HMAC-MD5 and key recovery attacks on sandwich-MAC-MD5 and MD5-MAC

  • Nippon Telegraph & Telephone
  • Donghua University
  • Nanyang Technological University

科研成果: 期刊稿件文章同行评审

摘要

This paper presents key recovery attacks on Sandwich- MAC instantiating MD5, where Sandwich-MAC is an improved variant of HMAC and achieves the same provable security level and better performance especially for short messages. The increased interest in lightweight cryptography motivates us to analyze such a MAC scheme. Our attacks are based on a distinguishing-H attack on HMAC-MD5 proposed by Wang et al. We first improve its complexity from 297 to 289.04. With this improvement, we then propose key recovery attacks on Sandwich-MAC-MD5 by combining various techniques such as distinguishing-H for HMAC-MD5, IV Bridge for APOP, dBB-near-collisions for related-key NMAC-MD5, meet-in-the-middle attack etc. In particular, we generalize a previous keyrecovery technique as a new tool exploiting a conditional key-dependent distribution. Surprisingly, a key which is even longer than the tag size can be recovered without the knowledge of the key size. Finally, our attack also improves the previous partial-key (K1) recovery on MD5-MAC, and extends it to recover both of K1 and K2.

源语言英语
页(从-至)26-38
页数13
期刊IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences
E98A
1
DOI
出版状态已出版 - 1 1月 2015
已对外发布

学术指纹

探究 'Improved single-key distinguisher on HMAC-MD5 and key recovery attacks on sandwich-MAC-MD5 and MD5-MAC' 的科研主题。它们共同构成独一无二的学术指纹。

引用此