RIPEMD with two-round compress function is not collision-free

58Citations
Citations of this article
34Readers
Mendeley users who have this article in their library.

Abstract

In 1990 Rivest introduced the cryptographic hash function MD4. The compress function of MD4 has three rounds. After partial attacks against MD4 were found, the stronger mode RIPEMD was designed as a European proposal in 1992 (RACE project). Its compress function consists of two parallel lines of modified versions of MD4-compress. RIPEMD is currently being considered to become an international standard (ISO/IEC Draft 10118-3). However, in this paper an attack against RIPEMD is described, which leads to comparable results with the previously known attacks against MD4: The reduced versions of RIPEMD, where the first or the last round of the compress function is omitted, are not collision-free. Moreover, it turns out that the methods developed in this note can be applied to find collisions for the full MD4. © 1997 International Association for Cryptologic Research.

Cite

CITATION STYLE

APA

Dobbertin, H. (1997). RIPEMD with two-round compress function is not collision-free. Journal of Cryptology, 10(1), 51–69. https://doi.org/10.1007/s001459900019

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free