Discussion forum for
Cryptology ePrint Archive reports posted in
2009.
Please put the report number in the subject.
Re: 2009/033
Posted by:
Orr (IP Logged)
Date: 13 May 2009 20:36
A difference in the MSB, affects only other MSBs.
(in other words - the MSBs do not affect any other bit but the MSBs).
And for a given message (just fix the 31 LSBs of each message word and the entire chaining value), the MSBs of the eight output chaining value are a linear combination of the 16 message MSBs.
Because this is the case, it is easy to find collisions (just solve the required linear equations), second preimages (given a specific input to the compression function, flip the correct MSBs to obtain the same output).
Also, using the De Canniere and Rechberger attack from Crypto 2006, it is possible to find preimages of the compression function in time complexity of about 32*2^8.
(some of these observations were verified by Tor).