Distinguishing and Second-Preimage Attacks on CBC-Like MACs

Keting Jia,Xiaoyun Wang,Zheng Yuan,Guangwu Xu
DOI: https://doi.org/10.1007/978-3-642-10433-6_23
2009-01-01
Abstract:This paper first presents a new distinguishing attack on the CBC-MAC structure based on block ciphers in cipher block chaining (CBC) mode. This attack detects a CBC-like MAC from random functions. The second result of this paper is a second-preimage attack on the CBC-MAC, which is an extension of the attack of Brincat and Mitchell. The attack also covers MT-MAC, PMAC and MACs with three-key enciphered CBC mode. Instead of exhaustive search, both types of attacks are of birthday attack complexity.
What problem does this paper attempt to address?