Target Collisions for MD5 and Colliding X.509 Certificates for Different Identities.

Marc Stevens, Arjen K. Lenstra, Benne de Weger · TU/e Research Portal · 2006

One of us has shown how for any two target messages m1 and m2 , values b1 and b2 can effectively be constructed such that the concatenated values m1||b1 and m2||b2 collide under MD5. Although the practical attack potential of this construction of target collisions is limited, it is of greater concern than random collisions for MD5. In this note we present two MD5 based X.509 certificates with identical signatures but different public keys and di#erent Distinguished Name fields, whereas our previous construction required identical name fields. We speculate on other possibilities for abusing target collisions.

Read the paper · More papers on PaperTik