aRussian Technical Committee for Standardization (TC 26), Moscow
Abstract:
A class of hash functions with a special finalization round (containing the GOST R 34.11-94 hash function) is considered. For functions from this class we propose a new multicollision attack and show that by means of Wagner's method it is possible to construct a description of a large number of different collisions. For GOST R 34.11-94 hash function we propose a modification of the known collision attack using smaller amount of memory. We obtain lower estimate for the amount of memory permitting the modified attack to be faster than generic ones.
Key words:hash function, collision, multicollision, GOST R 34.11-94, Wagner's method.