Cryptology ePrint Archive: Report 2008/089

An improved preimage attack on MD2

Søren S. Thomsen

Abstract: This paper describes an improved preimage attack on the cryptographic hash function MD2. The attack has complexity equivalent to about $2^{73}$ evaluations of the MD2 compression function. This is to be compared with the previous best known preimage attack, which has complexity about $2^{97}$.

Category / Keywords: secret-key cryptography / Hash functions, MD2, preimage attack