Linear-XOR and additive checksums don't protect Damgård-Merkle hashes from generic attacks

  • Authors:
  • Praveen Gauravaram;John Kelsey

  • Affiliations:
  • Technical University of Denmark, Denmark and Queensland University of Technology, Australia;National Institute of Standards and Technology

  • Venue:
  • CT-RSA'08 Proceedings of the 2008 The Cryptopgraphers' Track at the RSA conference on Topics in cryptology
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We consider the security of Damgård-Merkle variants which compute linear-XOR or additive checksums over message blocks, intermediate hash values, or both, and process these checksums in computing the final hash value. We show that these Damgård-Merkle variants gain almost no security against generic attacks such as the long-message second preimage attacks of [10, 21] and the herding attack of [9].