应用科学学报 ›› 2015, Vol. 33 ›› Issue (5): 481-490.doi: 10.3969/j.issn.0255-8297.2015.05.003

• 通信工程 • 上一篇    下一篇

MD5加密模式的差分故障分析

沈璇1, 赵光耀2, 李超1,2, 李瑞林3   

  1. 1. 国防科技大学理学院, 长沙 410073;
    2. 国防科技大学计算机学院, 长沙 410073;
    3. 国防科技大学电子科学与工程学院, 长沙 410073
  • 收稿日期:2014-10-23 修回日期:2015-04-10 出版日期:2015-09-30 发布日期:2015-09-30
  • 通信作者: 李超,教授,博导,研究方向:编码密码理论及其应用,E-mail:academic_lc@163.com E-mail:academic_lc@163.com
  • 基金资助:

    国家自然科学基金(No.61402515);湖南省教育厅科研项目基金(No.YB2014B001)资助

Differential Fault Analysis on Encryption Mode of MD5

SHEN Xuan1, ZHAO Guang-yao2, LI Chao1,2, LI Rui-lin3   

  1. 1. College of Science, National University of Defense Technology, Changsha 410073, China;
    2. College of Computer Science, National University of Defense Technology, Changsha 410073, China;
    3. College of Electronic Science and Engineering, National University of Defense Technology, Changsha 410073, China
  • Received:2014-10-23 Revised:2015-04-10 Online:2015-09-30 Published:2015-09-30

摘要: 通过研究MD5 加密模式中轮函数的差分特性,给出了一个求解差分方程的快速算法,可以实现从倒数第3 轮对MD5 加密模式进行差分故障分析. 研究结果表明,若从倒数第3 轮开始导入故障,平均只需56 个故障即可成功恢复512 bit 的种子密钥.

关键词: MD5, 加密模式, 差分特性, 快速算法, 差分故障分析

Abstract: By studying differential properties of the round functions in the encryption mode of MD5, we propose a fast algorithm to solve the differential equation. We give a differential fault analysis on the encryption mode of MD5 from the third last round with the proposed algorithm. The result shows that, if we induce faults from the third last round, only 56 random faults in average are required to obtain 512 bit key successfully.

Key words: MD5, encryption mode, differential property, fast algorithm, differential fault analysis

中图分类号: