Title
Collision Attacks against the Knudsen-Preneel Compression Functions
Abstract
Knudsen and Preneel (Asiacrypt'96 and Crypto'97) introduced a hash function design in which a linear error-correcting code is used to build a wide-pipe compression function from underlying blockciphers operating in Davies-Meyer mode. Their main design goal was to deliver compression functions with collision resistance up to, and even beyond, the block size of the underlying blockciphers. In this paper, we present new collision-finding attacks against these compression functions using the ideas of an unpublished work of Watanabe and the preimage attack of Ozen, Shrimpton, and Stain (FSE'10). In brief, our best attack has a time complexity strictly smaller than the block-size for all but two of the parameter sets. Consequently, the time complexity lower bound proven by Knudsen and Preneel is incorrect and the compression functions do not achieve the security level they were designed for.
Year
DOI
Venue
2010
10.1007/978-3-642-17373-8_5
ADVANCES IN CRYPTOLOGY - ASIACRYPT 2010
Keywords
DocType
Volume
Collision attack,coding theory,compression function
Conference
6477
ISSN
Citations 
PageRank 
0302-9743
2
0.35
References 
Authors
13
2
Name
Order
Citations
PageRank
Onur Özen12368.61
Martijn Stam2165967.36