Updates on generic attacks against HMAC and NMAC

15Citations
Citations of this article
32Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

In this paper, we present new generic attacks against HMAC and other similar MACs when instantiated with an n-bit output hash function maintaining a l-bit internal state. Firstly, we describe two types of selective forgery attacks (a forgery for which the adversary commits on the forged message beforehand). The first type is a tight attack which requires O(2l/2) computations, while the second one requires O(22l/3) computations, but offers much more freedom degrees in the choice of the committed message. Secondly, we propose an improved universal forgery attack which significantly reduces the complexity of the best known attack from O(25l/6) to O(23l/4). Finally, we describe the very first time-memory tradeoff for key recovery attack on HMAC. With O(2l) precomputation, the internal key Kout is firstly recovered with O(22l/3) computations by exploiting the Hellman's time-memory tradeoff, and then the other internal key Kin is recovered with O(23l/4) computations by a novel approach. This tends to indicate an inefficiency in using long keys for HMAC. © 2014 International Association for Cryptologic Research.

Cite

CITATION STYLE

APA

Guo, J., Peyrin, T., Sasaki, Y., & Wang, L. (2014). Updates on generic attacks against HMAC and NMAC. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8616 LNCS, pp. 131–148). Springer Verlag. https://doi.org/10.1007/978-3-662-44371-2_8

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free