| B. Schneier, "One-way hash functions," Dr. Dobb's Journal,Vol. 16, No. 9, 1991, pp. 148--151. |
....a work load of finding about 2 16 collisions for the first two rounds of the MD5 compression function to find a collision for the entire four round function. On a 33MHz 80386 based PC the mean run time of this program is about 4 minutes. 1 Introduction The MD5 Message Digest Algorithm [Rive91,Rive92b,Schn91] introduced by Ronald L. Rivest at Crypto 91 as a strengthened version of MD4 [Rive90, Rive92a] differs from MD4 on the following points: A fourth round has been added. The second round function has been changed from the majority function XY XZ YZ to the multiplexer function XZ Y Z . ....
....and numbered from 1 2 Round i 1 2 3 4 si1 7 5 4 6 si2 12 9 11 10 si3 17 14 16 15 si4 22 20 23 21 Table 1. The 16 different shift constants of MD5 (step 1 of round 1) through 48 (step 16 of round 4) For a complete specification of MD5 the reader is referred to the original description [Rive92b,Schn91]. Note that in this original description of MD5 the designation f , g, h and i are used for respectively the round functions f 1 , f 2 , f 3 and f 4 . 3 Description of the collision search algorithm First the condition imposed on two inputs to produce the same image under the compression ....
B. Schneier, "One-way hash functions," Dr. Dobb's Journal,Vol. 16, No. 9, 1991, pp. 148--151.
....a work load of finding about 2 16 collisions for the first two rounds of the MD5 compression function to find a collision for the entire four round function. On a 33MHz 80386 based PC the mean run time of this program is about 4 minutes. 1 Introduction The MD5 Message Digest Algorithm [Rive91, Rive92b, Schn91] introduced by Ronald L. Rivest at Crypto 91 as a strengthened version of MD4 [Rive90, Rive92a] differs from MD4 on the following points: A fourth round has been added. The second round function has been changed from the majority function XY XZ Y Z to the multiplexer function XZ Y Z . ....
....and numbered from 1 2 Round i 1 2 3 4 si1 7 5 4 6 si2 12 9 11 10 si3 17 14 16 15 si4 22 20 23 21 Table 1. The 16 different shift constants of MD5 (step 1 of round 1) through 48 (step 16 of round 4) For a complete specification of MD5 the reader is referred to the original description [Rive92b, Schn91]. Note that in this original description of MD5 the designation f , g, h and i are used for respectively the round functions f 1 , f 2 , f 3 and f 4 . 3 Description of the collision search algorithm First the condition imposed on two inputs to produce the same image under the compression ....
B. Schneier, "One-way hash functions," Dr. Dobb's Journal, Vol. 16, No. 9, 1991, pp. 148--151.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC