An improved preimage attack on MD2

Abstract

This paper describes an improved preimage attack on the cryptographic hash function MD2. The attack has complexity equivalent to about 2732^{73} evaluations of the MD2 compression function. This is to be compared with the previous best known preimage attack, which has complexity about 2972^{97}

    Similar works