On a Conditional Collision Attack on NaSHA-512
Smile Markovski, Aleksandra Mileva, Vesna Dimitrova, Danilo Gligoroski · Goce Delchev University Repository (Goce Delčev University of Štip) · 2009
A collision attack on NaSHA-512 was proposed by L. Ji et al. The claimed complexity of the attack is 2^{192}. The proposed attack is realized by using a suitable differential pattern. In this note we show that the correct result that can be inferred from their differential pattern is in fact a conditional one. It can be stated correctly as follows: A collision attack on NaSHA-512 of complexity k = 1, 2, ... 2^{320} can be performed with an unknown probability of success p_k, where 0 <= p_1 <=p_2 <= p_2^{320} <= 1. Consequently, the attack proposed by L. Ji et al. can be considered only as a direction how a possible collision attack on NaSHA-512 could be realized. The birthday attack remains the best possible attack on NaSHA-512.