对全轮RIPEMD-128的改进区分攻击OA
Improved Distinguishing Attack on Full RIPEMD-128
RIPEMD 系列哈希函数在 PGP 和比特币等实际应用环境中广泛使用,其中 RIPEMD-128 于2003 年被 ISO/IEC 纳入标准.本文对 RIPEMD-128 提出了一个全轮的区分攻击,并降低了攻击的复杂性.RIPEMD-128 的基本结构是由两条并行的 MD4 组成,为此,本文使用差分攻击,并利用由 Wang 和Yu 提出的比特追踪技术为 RIPEMD-128 的 Line1 及 Line2 的双线并行操作分别找到了更好的差分路线.此外,除使用消息修改技术满足 Line2 中的大多数条件外,还使用消息对(m11,m15)修改 Line1 中的若干条件,进一步将攻击的复杂度减少到 298.最后,转换分析的角度,给出了将本文攻击放在量子环境下的分析结果.理论上,量子攻击的复杂度将变为 249.本文结果可能有助于改进对 RIPEMD-128 的攻击.
RIPEMD hash functions have been widely used in practical applications such as PGP and Bitcoin,among which RIPEMD-128 was standardized by ISO/IEC in 2003.This sudy presents a distinguishing attack on the full-round RIPEMD-128 and further reduces its attack complexity.Since the basic structure of RIPEMD-128 consists of two parallel MD4-like lines,differential cryptanalysis is employed and the bit-tracing technique proposed by Wang and Yu is utilized to construct improved differential characteristics for both Line1 and Line2 of the dual-line parallel structure.In addition,besides using message modification techniques to satisfy most conditions in Line2,several conditions in Line1 are further modified through the message pair(m11,m15),thereby reducing the attack complexity to 298.Finally,by shifting the perspective of analysis,the proposed attack is investigated in the quantum setting.Theoretically,the complexity of the quantum attack can be reduced to 249.The results of this study may contribute to further improvements in attacks on RIPEMD-128.
曹荣蓉;卢政荣;于红波
清华大学 计算机科学与技术系,北京 100084清华大学 计算机科学与技术系,北京 100084清华大学 计算机科学与技术系,北京 100084||清华大学 密码与数字经济安全全国重点实验室,北京 100084
信息技术与安全科学
RIPEMD-128区分攻击差分路线消息修改中性比特量子攻击
RIPEMD-128distinguishing attackdifferential characteristicmessage modificationneutral bitsquantum attack
《密码学报(中英文)》 2026 (2)
268-282,15
国家密码科学基金(2025NCSF02014)National Cryptologic Science Fund of China(2025NCSF02014)
评论