消息认证码(MAC)是保证消息完整性的重要工具,它广泛应用于各种安全系统中。基于分组密码构建各种MAC(消息认证码)是目前的研究热点之一。近来,C.Mitchell提出了一种新的工作模式即TMAC—V,并声称该工作模式是安全有效的。文中利用随机消息的碰撞特性,给出了一种新的消息伪造攻击方法,并指出新攻击下TMAC—V工作模式是脆弱的:利用我们的新方法可以成功的进行消息和其MAC的伪造.与已有的攻击方法相比,我们发现该新攻击所需的碰撞条件更为宽松,并使得实施攻击更为灵活、有效。
Message Authentication Code (MAC) plays an important role in protecting the integrity of message, which is extensively used in various security systems. Currently, one of research hotspot is how to construct a secure MAC (i. e. Message Authentication Code) based on block cipher. Recently, C. Mitchell proposes a new MAC mode i.e., TMAC-V, Which is provably secure and efficient. However, this paper, presents a new message forgery attack on TMAC-V by using the property of stochastic collision, it further indicates that TMAC-V scheme is vulnerable to the new message forgery attack, i.e. the adversary can forge the message and its MAC successfully. Compared with the previous attack, it seems that this new message forgery attack is more flexible and effective.