Wang's sufficient conditions of MD5 are not sufficient

Jun Yajima and Takeshi Shimoyama

Abstract: In this paper, we report that the "sufficient conditions" of MD5 of the modification technique for the collision search algorithm described by Wang are not sufficient. In our analysis, we show at least 4 extra-conditions for the message modification in the first block and corrections of the several conditions which are correspond to the highest (32nd) bit of the sufficient conditions in the second block should be needed. And we show the new collision message which is completely different from the message pairs showed by Wang by using our extended sufficient conditions.

Category / Keywords: secret-key cryptography / hash function, MD5, Collision, sufficient condition, message modification

Date: received 10 Aug 2005, last revised 10 Aug 2005

Contact author: jyajima at labs fujitsu com

Version: 20050811:072704 (All versions of this report)

