New Distinguishing Attack on MAC Using Secret-Prefix Method

Xiaoyun Wang,Wei Wang,Keting Jia,Meiqin Wang
DOI: https://doi.org/10.1007/978-3-642-03317-9_22
2009-01-01
Abstract:This paper presents a new distinguisher which can be applied to secret-prefix MACs with the message length prepended to the message before hashing. The new distinguisher makes use of a special truncated differential path with high probability to distinguish an inner near-collision in the first round. Once the inner near-collision is detected, we can recognize an instantiated MAC from a MAC with a random function. The complexity for distinguishing the MAC with 43-step reduced SHA-1 is 2124.5 queries. For the MAC with 61-step SHA-1, the complexity is 2154.5 queries. The success probability is 0.70 for both.
What problem does this paper attempt to address?