On the security of the digest function in the SARI image authentication system

  • Authors:
  • R. Radhakrishnan;N. Memon

  • Affiliations:
  • Dept. of Electr. & Comput. Eng., Polytech. Univ. Brooklyn, NY;-

  • Venue:
  • IEEE Transactions on Circuits and Systems for Video Technology
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

We investigate the image authentication system SARI, proposed by Lin and Chang (see ibid., vol.11, p.153-68, Feb. 2001), that distinguishes JPEG compression from malicious manipulations. In particular, we took at the image digest component of this system. We show that if multiple images have been authenticated with the same secret key and the digests of these images are known to an attacker, Oscar, then he can cause arbitrary images to be authenticated with this same but unknown key. We show that the number of such images needed by Oscar to launch a successful attack is quite small, making the attack very practical. We then suggest possible solutions to enhance the security of this authentication system.