This paper presents the first equivalent key recovery attack on H2-MAC-MD5, which conduces to a selective forgery attack directly. H2-MAC is similar with HMAC except that the outer key is omitted. For HMAC-MD5, since the available differential paths are pseudo- collisions, all the key recovery attacks are in the related-key setting, while our attack on H2- MAC-MD5 gets rid of this restriction. Based on the distinguisher of HMAC-MD5 proposed by Wang et al., a pair of intermediate chaining variables, i.e., the equivalent keys ( ˜K , ˜K ′), is detected which fulfils the specific conditions on (IV, IV ′) of the pseudo-collision. Then the inner key recovery attack on HMAC-MD5 explored by Contini and Yin is adopted to recover ( ˜K , ˜K ′). Consequently, the adversary can compute the valid MAC value of M0kM∗ effortlessly, where M0 is a fixed one-block message, and M∗ can be any bit string. Keywords: Cryptanalysis, H2-MAC-MD5, Distinguishing attack, Equivalent key recovery attack
목차
Abstract 1 Introduction 2 Preliminaries 2.1 Notations 2.2 Brief Description of MD5 2.3 Pseudo-collisions of MD5 2.4 Brief Description of H2-MAC 3 Equivalent Key Recovery Attack on H2-MAC-MD5 3.1 Distinguishing Attack on H2-MAC-MD5 3.2 Recovering the Equivalent Key ˜K 3.3 Selective Forgery Attack 4 Conclusions References
저자
Wei Wang [ School of Computer Science and Technology, Shandong University, Key Laboratory of Cryptologic Technology and Information Security, Ministry of Education, Shandong University ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.6 No.1