On the (in)security of IDEA in various hashing modes


Autoria(s): Wei, Lei; Peyrin, Thomas; Sokołowski, Przemysław; San, Ling; Pieprzyk, Josef; Wang, Huaxiong
Data(s)

2012

Resumo

In this article, we study the security of the IDEA block cipher when it is used in various simple-length or double-length hashing modes. Even though this cipher is still considered as secure, we show that one should avoid its use as internal primitive for block cipher based hashing. In particular, we are able to generate instantaneously free-start collisions for most modes, and even semi-free-start collisions, pseudo-preimages or hash collisions in practical complexity. This work shows a practical example of the gap that exists between secret-key and known or chosen-key security for block ciphers. Moreover, we also settle the 20-year-old standing open question concerning the security of the Abreast-DM and Tandem-DM double-length compression functions, originally invented to be instantiated with IDEA. Our attacks have been verified experimentally and work even for strengthened versions of IDEA with any number of rounds.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/70089/

Publicador

Springer Berlin Heidelberg

Relação

http://eprints.qut.edu.au/70089/2/Draft_paper_JP.pdf

DOI:10.1007/978-3-642-34047-5_10

Wei, Lei, Peyrin, Thomas, Sokołowski, Przemysław, San, Ling, Pieprzyk, Josef, & Wang, Huaxiong (2012) On the (in)security of IDEA in various hashing modes. Lecture Notes in Computer Science : Fast Software Encryption, 7549, pp. 163-179.

Direitos

Springer-Verlag Berlin Heidelberg

Fonte

School of Electrical Engineering & Computer Science; Science & Engineering Faculty

Palavras-Chave #IDEA #Block cipher #Hash function #Cryptanalysis #Collision #Preimage
Tipo

Journal Article