(Enter summary)
Abstract: Cryptographic primitives are usually based on a network with some
gates. In [SV94], it is claimed that all gates should be multipermutations.
In this paper, we investigate a few combinatorial properties of multipermutations.
We argue that gates which fail to be multipermutations can
open the way to unsuspected attacks. We illustrate this statement with
two examples.
Firstly, we show how to construct collisions to MD4 restricted to its first
two rounds. This allows to forge digests close to each ... (Update)
Context of citations to this paper: More
.... some collisions on the first 2 rounds of MD4 using the fact that the diffusion boxes in these rounds are not multipermutations [13]. The design of cryptographic primitives then leads to the search of multipermutations over a given alphabet F . Proposition 5 enables us...
...orders except n = 2 or n = 6. Shannon[15] observed that latin squares are useful in cryptography; more recently Schnorr and Vaudenay[14, 16] applied pairs of orthogonal latin squares (which they called multipermutations) to cryptography. Since the focus of this paper is on...
Cited by: More
Near-Collisions of SHA-0 - Eli Biham Ra (2004)
(Correct)
On the Design of Linear Transformations for Substitution .. - Youssef, Mister, Tavares (1997)
(Correct)
Permutation Polynomials Modulo 2 - Rivest (1999)
(Correct)
Active bibliography (related documents): More All
0.5: The Strength of the CCITT/ISO Hash Function - Jung (1996)
(Correct)
0.3: Black Box Cryptanalysis of Hash Networks based on.. - Schnorr, Vaudenay (1994)
(Correct)
0.3: On Check Digit Systems using Anti-symmetric Mappings - Schulz (1999)
(Correct)
Similar documents based on text: More All
0.6: Parallel FFT-Hashing - Schnorr, Vaudenay (1994)
(Correct)
0.5: Generalization of Siegenthaler Inequality and.. - Camion, Canteaut (1996)
(Correct)
0.4: Provable security for block Ciphers by decorrelation - Vaudenay (1998)
(Correct)
Related documents from co-citation: More All
6: Federal information processing standards publication 140-1: Security requirement.. (context) - Institute, andTechnology - 1994
5: a byte-oriented block-ciphering algorithm (context) - Massey - 1994
5: Analysis and Design of Cryptographic Hash Functions (context) - Preneel - 1993
BibTeX entry: (Update)
S. Vaudenay. On the need for Multipermutations: Cryptanalysis of MD4 and SAFER. In Proceedings of the Leuven Workshop on Cryptographic Algorithms, pages 195--206, 1994. http://citeseer.ist.psu.edu/vaudenay94need.html More
@inproceedings{ vaudenay94need,
author = "Serge Vaudenay",
title = "On the Need for Multipermutations: Cryptanalysis of MD4 and {SAFER}",
booktitle = "Fast Software Encryption",
pages = "286-297",
year = "1994",
url = "citeseer.ist.psu.edu/vaudenay94need.html" }
Citations (may not include all citations):
1749
An Introduction to Probability Theory and its Applications (context) - Feller - 1957
860
The theory of error-correcting codes (context) - McWilliams, Sloane - 1977
401
The MD4 Message Digest algorithm (context) - Rivest - 1991
288
Linear cryptanalysis method for DES cipher (context) - Matsui - 1994
80
The first experimental cryptanalysis of the Data Encryption .. (context) - Matsui - 1994
77
One way hash functions and DES (context) - Merkle - 1990
61
A design principle for hash functions (context) - Damgard - 1990
52
Latin squares and their applications (context) - D'enes, Keedwell - 1974
39
Linear cryptanalysis using multiple approximations (context) - Jr, Robshaw - 1994
32
a byte-oriented block-ciphering algorithm (context) - Massey - 1994
17
Generating strong one-way functions with cryptographic algor.. (context) - Matyas, Meyer et al. - 1985
13
Black box cryptanalysis of hash networks based on multipermu..
- Schnorr, Vaudenay
13
An attack on the last two rounds of MD
- den Boer, Bosselaers - 1992
3
Complete mappings of finite groups (context) - Hall, Paige - 1955
2
Digital signature -- an update (context) - Davies, Price - 1985
The graph only includes citing articles where the year of publication is known.
Documents on the same site (http://fermivista.math.jussieu.fr/ftp/ftp.ens.fr.html): More
A Decompositional Approach for Computing Least Fixed-Points.. - Fribourg, Olsen (1996)
(Correct)
The MLgraph Primer - Chailloux, Cousineau (1992)
(Correct)
Counter-examples to Ragsdale Conjecture - Itenberg (1993)
(Correct)
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC