Differential and invertibility properties of BLAKE (full version)

نویسندگان

  • Jean-Philippe Aumasson
  • Jian Guo
  • Simon Knellwolf
  • Krystian Matusiewicz
  • Willi Meier
چکیده

BLAKE is a hash function selected by NIST as one of the 14 second round candidates for the SHA-3 Competition. In this paper, we follow a bottom-up approach to exhibit properties of BLAKE and of its building blocks: based on differential properties of the internal function G, we show that a round of BLAKE is a permutation on the message space, and present an efficient inversion algorithm. For 1.5 rounds we present an algorithm that finds preimages faster than in previous attacks. Discovered properties lead us to describe large classes of impossible differentials for two rounds of BLAKE’s internal permutation, and particular impossible differentials for five and six rounds, respectively for BLAKE32 and BLAKE-64. Then, using a linear and rotation-free model, we describe near-collisions for four rounds of the compression function. Finally, we discuss the problem of establishing upper bounds on the probability of differential characteristics for BLAKE.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Differential and Invertibility Properties of BLAKE

BLAKE is a hash function selected by NIST as one of the 14 second round candidates for the SHA-3 Competition. In this paper, we follow a bottom-up approach to exhibit properties of BLAKE and of its building blocks: based on differential properties of the internal function G, we show that a round of BLAKE is a permutation on the message space, and present an efficient inversion algorithm. For 1....

متن کامل

Analysis of BLAKE2

We present a thorough security analysis of the hash function family BLAKE2, a recently proposed and already in use tweaked version of the SHA-3 finalist BLAKE. We study how existing attacks on BLAKE apply to BLAKE2 and to what extent the modifications impact the attacks. We design and run two improved searches for (impossible) differential attacks — the outcomes suggest higher number of attacke...

متن کامل

On Invertibility of Sobolev Mappings

We prove local and global invertibility of Sobolev solutions of certain differential inclusions which prevent the differential matrix from having negative eigenvalues. Our results are new even for quasiregular mappings in two dimensions.

متن کامل

Linear Maps Preserving Invertibility or Spectral Radius on Some $C^{*}$-algebras

Let $A$ be a unital $C^{*}$-algebra which has a faithful state. If $varphi:Arightarrow A$ is a unital linear map which is bijective and invertibility preserving or surjective and spectral radius preserving, then $varphi$ is a Jordan isomorphism. Also, we discuss other types of linear preserver maps on $A$.

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2010  شماره 

صفحات  -

تاریخ انتشار 2010