Re: SHA-1 Variants

From: Anton Stiglic (stiglic_at_cs.mcgill.ca)
Date: 06/03/04


Date: Thu, 3 Jun 2004 15:20:10 -0400


"Mok-Kong Shen" <mok-kong.shen@t-online.de> wrote in message
news:c9nisv$6lf$00$1@news.t-online.com...

> A related question: Could someone please give a few good
> references that formally deal with the security of SHA? Thanks.
>
> M. K. Shen

For starters, you can take a look at

Analysis of SHA-1 in Encryption Mode,
Helena Handschuh, Lars R. Knudsen, Matthew J. Robshaw
http://www.gemplus.com/smart/r_d/publications/pdf/HKR01sha.pdf

and

Cryptanalysis of Block Ciphers Based on SHA-1 and MD5,
Markku-Juhani O. Saarinen
www.tcs.hut.fi/~mjos/doc/shaan.ps

which look at the SHA-1 compression function as a block cipher.

There have also been results on MD4 and MD5, some of which
can clarify things about the design of SHA-1. Also look at the
attack on SHA-0.
Basically, the advantage of using SHA-1 is that it has been around
for a while and hasn't gotten broken yet.

--Anton



Relevant Pages

  • Re: This Weeks Finds in Mathematical Physics (Week 226)
    ... Yeah, I said SHA-1 and MD5 are different, and I said they were both vulnerable ... Attacking hash functions by poisoned ... where Ldenotes the length of the axiom system A, ...
    (sci.physics.research)
  • Re: Re-secured Algorithm?
    ... >>MD5 collisions are actually trivial to generate. ... SHA-1 had real collisions in MD5. ... Personal attacks aside I doubt many ...
    (sci.crypt)
  • Re: Crypto Hash functions
    ... crypto-hash functions were "broken". ... MD5: ... SHA-1: wounded but still fighting. ... If you're signing bulk data, probably SHA-256 is your best bet. ...
    (sci.crypt)
  • Re: Crypto Hash functions
    ... crypto-hash functions were "broken". ... MD5: ... SHA-1: wounded but still fighting. ... If you're signing bulk data, probably SHA-256 is your best bet. ...
    (sci.crypt)
  • RE: sha-1 cryptography
    ... MD5 and SHA-1 are not used to ensure Confidentiality, ... the confidentiality of passwords or credit card numbers or the ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)

Loading