Skip to main navigation Skip to search Skip to main content

The Rebound Attack and Subspace Distinguishers: Application to Whirlpool

  • Mario Lamberger
  • , Florian Mendel
  • , Martin Schläffer
  • , Christian Rechberger
  • , Vincent Rijmen
  • NXP Semiconductors Austria
  • Graz University of Technology
  • Stichting Katholieke Universiteit

Research output: Contribution to journalJournal articleResearchpeer-review

Abstract

We introduce the rebound attack as a variant of differential cryptanalysis on hash functions and apply it to the hash function Whirlpool, standardized by ISO/IEC. We give attacks on reduced variants of the 10-round Whirlpool hash function and compression function. Our results are collisions for 5.5 and near-collisions for 7.5 rounds on the hash function, as well as semi-free-start collisions for 7.5 and semi-free-start near-collisions for 9.5 rounds on the compression function. Additionally, we introduce the subspace problem as a generalization of near-collision resistance. Finally, we present the first distinguishers that apply to the full compression function and the full underlying block cipher W of Whirlpool.
Original languageEnglish
JournalJournal of Cryptology
Volume28
Issue number2
Pages (from-to)257-296
Number of pages40
ISSN0933-2790
DOIs
Publication statusPublished - 2015

Keywords

  • Cryptanalysis
  • Distinguisher
  • Hash functions
  • Near-collision

Fingerprint

Dive into the research topics of 'The Rebound Attack and Subspace Distinguishers: Application to Whirlpool'. Together they form a unique fingerprint.

Cite this