Cryptology ePrint Archive: Report 2005/247

A Simple and Provably Good Code for SHA Message Expansion

Charanjit S. Jutla and Anindya C. Patthak

Abstract: We develop a new computer assisted technique for lower bounding the minimum distance of linear codes similar to those used in SHA-1 message expansion. Using this technique, we prove that a modified SHA-1 like code has minimum distance at least 82, and that too in just the last 64 of the 80 expanded words. Further the minimum weight in the last 60 words (last 48 words) is at least 75 (52 respectively). We propose a new compression function which is identical to SHA-1 except for the modified message expansion code. We argue that the high minimum weight of the message expansion code makes the new compression function resistant to recent differential attacks.

Category / Keywords: Hash Functions, Differential Cryptanalysis, Codes, minimum distance

Date: received 27 Jul 2005, last revised 5 Aug 2005

Contact author: csjutla at us ibm com

Available format(s): Postscript (PS) | Compressed Postscript (PS.GZ) | PDF | BibTeX Citation

Version: 20050805:220515 (All versions of this report)

Short URL:

Discussion forum: Show discussion | Start new discussion

[ Cryptology ePrint archive ]