International Association for Cryptologic Research (IACR)
Abstract
This paper describes an improved preimage attack on the cryptographic hash function MD2. The attack has complexity equivalent to about 273 evaluations of the MD2 compression function. This is to be compared with the previous best known preimage attack, which has complexity about 297