Preimages for Reduced-Round Tiger

  • Authors:
  • Sebastiaan Indesteege;Bart Preneel

  • Affiliations:
  • Dept. ESAT/SCD-COSIC, Katholieke Universiteit Leuven, Heverlee, Belgium B-3001;Dept. ESAT/SCD-COSIC, Katholieke Universiteit Leuven, Heverlee, Belgium B-3001

  • Venue:
  • Research in Cryptology
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The cryptanalysis of the cryptographic hash function Tiger has, until now, focussed on finding collisions. In this paper we describe a preimage attack on the compression function of Tiger-12, i.e., Tiger reduced to 12 rounds out of 24, with a complexity of 263.5 compression function evaluations. We show how this can be used to construct second preimages with complexity 263.5 and first preimages with complexity 264.5 for Tiger-12. These attacks can also be extended to Tiger-13 at the expense of an additional factor of 264 in complexity.