See this document in CiteSeerX!

On the Need for Multipermutations: Cryptanalysis of MD4 and SAFER (1994)  (Make Corrections)  (14 citations)
Serge Vaudenay
Fast Software Encryption



  Home/Search   Context   Related

 
View or download:
ens.fr/pub/dmi/use...iens9423.A4.ps.Z
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  fermivista.math.juss...ftp.ens.fr (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: Cryptographic primitives are usually based on a network with some gates. In [SV94], it is claimed that all gates should be multipermutations. In this paper, we investigate a few combinatorial properties of multipermutations. We argue that gates which fail to be multipermutations can open the way to unsuspected attacks. We illustrate this statement with two examples. Firstly, we show how to construct collisions to MD4 restricted to its first two rounds. This allows to forge digests close to each ... (Update)

Context of citations to this paper:   More

.... some collisions on the first 2 rounds of MD4 using the fact that the diffusion boxes in these rounds are not multipermutations [13]. The design of cryptographic primitives then leads to the search of multipermutations over a given alphabet F . Proposition 5 enables us...

...orders except n = 2 or n = 6. Shannon[15] observed that latin squares are useful in cryptography; more recently Schnorr and Vaudenay[14, 16] applied pairs of orthogonal latin squares (which they called multipermutations) to cryptography. Since the focus of this paper is on...

Cited by:   More
Near-Collisions of SHA-0 - Eli Biham Ra (2004)   (Correct)
On the Design of Linear Transformations for Substitution .. - Youssef, Mister, Tavares (1997)   (Correct)
Permutation Polynomials Modulo 2 - Rivest (1999)   (Correct)

Active bibliography (related documents):   More   All
0.5:   The Strength of the CCITT/ISO Hash Function - Jung (1996)   (Correct)
0.3:   Black Box Cryptanalysis of Hash Networks based on.. - Schnorr, Vaudenay (1994)   (Correct)
0.3:   On Check Digit Systems using Anti-symmetric Mappings - Schulz (1999)   (Correct)

Similar documents based on text:   More   All
0.6:   Parallel FFT-Hashing - Schnorr, Vaudenay (1994)   (Correct)
0.5:   Generalization of Siegenthaler Inequality and.. - Camion, Canteaut (1996)   (Correct)
0.4:   Provable security for block Ciphers by decorrelation - Vaudenay (1998)   (Correct)

Related documents from co-citation:   More   All
6:   Federal information processing standards publication 140-1: Security requirement.. (context) - Institute, andTechnology - 1994
5:   a byte-oriented block-ciphering algorithm (context) - Massey - 1994
5:   Analysis and Design of Cryptographic Hash Functions (context) - Preneel - 1993

BibTeX entry:   (Update)

S. Vaudenay. On the need for Multipermutations: Cryptanalysis of MD4 and SAFER. In Proceedings of the Leuven Workshop on Cryptographic Algorithms, pages 195--206, 1994. http://citeseer.ist.psu.edu/vaudenay94need.html   More

@inproceedings{ vaudenay94need,
    author = "Serge Vaudenay",
    title = "On the Need for Multipermutations: Cryptanalysis of MD4 and {SAFER}",
    booktitle = "Fast Software Encryption",
    pages = "286-297",
    year = "1994",
    url = "citeseer.ist.psu.edu/vaudenay94need.html" }
Citations (may not include all citations):
1749   An Introduction to Probability Theory and its Applications (context) - Feller - 1957
860   The theory of error-correcting codes (context) - McWilliams, Sloane - 1977
401   The MD4 Message Digest algorithm (context) - Rivest - 1991
288   Linear cryptanalysis method for DES cipher (context) - Matsui - 1994
80   The first experimental cryptanalysis of the Data Encryption .. (context) - Matsui - 1994
77   One way hash functions and DES (context) - Merkle - 1990
61   A design principle for hash functions (context) - Damgard - 1990
52   Latin squares and their applications (context) - D'enes, Keedwell - 1974
39   Linear cryptanalysis using multiple approximations (context) - Jr, Robshaw - 1994
32   a byte-oriented block-ciphering algorithm (context) - Massey - 1994
17   Generating strong one-way functions with cryptographic algor.. (context) - Matyas, Meyer et al. - 1985
13   Black box cryptanalysis of hash networks based on multipermu.. - Schnorr, Vaudenay
13   An attack on the last two rounds of MD - den Boer, Bosselaers - 1992
3   Complete mappings of finite groups (context) - Hall, Paige - 1955
2   Digital signature -- an update (context) - Davies, Price - 1985



The graph only includes citing articles where the year of publication is known.


Documents on the same site (http://fermivista.math.jussieu.fr/ftp/ftp.ens.fr.html):   More
A Decompositional Approach for Computing Least Fixed-Points.. - Fribourg, Olsen (1996)   (Correct)
The MLgraph Primer - Chailloux, Cousineau (1992)   (Correct)
Counter-examples to Ragsdale Conjecture - Itenberg (1993)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC