Analysis of CRC Methods and Potential Data Integrity Exploits

B. Maxwell, G. Amerson, Liaquat Roopesh Johnson · 2003

Cyclic redundancy checks (CRCs) are commonly used to detect errors from noise in networks. They also have been used to verify the integrity of files in a system to prevent tampering and suggested as a possible algorithm for manipulation detection codes. It has been known that a CRC will not detect all errors but with random noise it is unlikely. But a malevolent adversary can efficiently modify a file without changing its length to maintain the same CRC. In this paper, we present an efficient algorithm for modifying an individual byte of a file and other additional bytes to maintain the same CRC. A previous attack on CRC padded a file with additional bytes to maintain the same CRC. In this work, the original file length is maintained and it demonstrates that a CRC, although good for error detection, may not be the best choice for a hash function without additional modifications.

Read the paper · More papers on PaperTik