海归网首页   海归宣言   导航   博客   广告位价格  
海归论坛首页 会员列表 
收 藏 夹 
论坛帮助 
登录 | 登录并检查站内短信 | 个人设置 论坛首页 |  排行榜  |  在线私聊 |  专题 | 版规 | 搜索  | RSS  | 注册 | 活动日历
主题: 密码学领域重大发现:山东大学王小云教授成功破解MD5(ZT)
回复主题   printer-friendly view    海归论坛首页 -> 海归商务           焦点讨论 | 精华区 | 嘉宾沙龙 | 白领丽人沙龙
  阅读上一个主题 :: 阅读下一个主题
作者 密码学领域重大发现:山东大学王小云教授成功破解MD5(ZT)   
所跟贴 密码学领域重大发现:山东大学王小云教授成功破解MD5(ZT) -- 游客 - (5167 Byte) 2004-9-08 周三, 06:27 (2520 reads)
孤枕难眠
[博客]
[个人文集]




头衔: 海归中将

头衔: 海归中将
声望: 学员
性别: 性别:女
加入时间: 2004/02/24
文章: 3573
来自: 美国
海归分: 411670





文章标题: Digital Signature Concerns Emerge (ZT) (790 reads)      时间: 2004-9-08 周三, 13:14   

作者:孤枕难眠海归商务 发贴, 来自【海归网】 http://www.haiguinet.com

By Elizabeth Millard
from https://www.technewsworld.com/story/35926.html

At this week's Crypto 2004 conference in California, several papers were presented that demonstrated vulnerabilities in algorithms that are often used to create digital signatures. Although the results are preliminary, many in the security community are concerned about what such weaknesses might mean for digital signature use in the future.

The algorithms in question are MD5, with is often used with digital signatures, as well as SHA-0 and SHA-1, both popular in security development.

Even though there is buzz about the reports, there is not much shock, said Steve Mathews, CEO of security firm ArticSoft and one of the authors of BS ISO/IEC 17799 Code of Practice for Information Security Management.

In an interview with LinuxInsider, Mathews stated, "I am not surprised by the news on MD5. There have been concerns in the technical communities for some time that there could be a weakness, and SHA-1 has been preferred."

He added that the implications for SHA-0 and SHA-1 are definitely a concern.


Unveiling the Weaknesses
The round of vulnerability announcements started on Thursday, when a French computer scientist, Antoine Joux, discussed a flaw he had found in MD5. Invented in 1991, MD5 has not had a reported vulnerability before.

The announcement immediately sparked concern because of the algorithm's popularity and use with the Apache Web server . Sun Microsystems (Nasdaq: SUNW) also uses MD5 in its Fingerprint Database product.

Mathews noted that his company's products only use SHA-1, but has to accept signatures using MD5 as well. He said, "We will likely have to include a 'health warning' for MD5 going forward."

Two more announcements, from Chinese and Israeli researchers, identified ways to circumvent security in SHA-0, and early results with vulnerabilities in SHA-1.

Certified by the National Institute of Standards and Technology in 1992, SHA-1 is used in programs like PGP and SSL, as well as in the U.S. government's Digital Signature Standard.

The conference's reports have prompted organizers to develop a Webcast on the topic of hash collisions, which will present additional findings.

Sign of the Times
The results of the announcements for the future of digital signatures is not yet known, but Stanford University security researcher Neil Daswani told LinuxInsider that "digital signature schemes will have to be modified to use other hash functions, if good candidates are available."

Researchers and developers might have some time to investigate such avenues, noted Mathews.

"As far as digital signatures are concerned, there are no indications that the SHA-based ones will become unreliable and we have to abandon current technologies, although it would be sensible to start looking for a new technique," he said.

Although MD5 and SHA-1 are popular, Daswani said many other hash algorithms have been proposed. It is likely that given the recent announcements, researchers will begin investigating these algorithms to discover new sources of security.

Ongoing Conversation
In general, programming is unlikely to be affected by vulnerabilities found in a few hash functions, according to Daswani. "However," he said, "the topic of developing secure hash functions may become more active in the security research community."

Mathews added that programmers will have to face the realization that a new, previously unknown attack against an algorithm scheme has been found, and progress from there. That could affect programming more broadly.

"That means designing systems where we can quickly add in new and dump out old," said Mathews. "There also needs to be a management system in place that allows this to happen."

He noted that such a system currently goes against most of the regulations governing the export of cryptography, which do not allow the customer to change algorithms that have been implemented. Changing the situation would allow for moving everyone affected by scheme breakdowns to move over to a new scheme quickly, cleanly and safely, said Mathews.

Such issues will likely be addressed in coming months as security researchers explore the implications of the conference's announcements more fully. "It's a bit like having Y2K again, with a bigger threat and less time to fix it," Mathews noted.

=========================================================

MD5 cracked by Xiaoyun Wang, et. al, not Antoine Joux
Posted by: valhenson 2004-08-18 13:41:15 In reply to: Elizabeth Millard
There is an error in attribution. Antoine Joux broke SHA-0, Xiaoyun Wang et al. broke MD5 (as well as RIPEMD, HAVAL-128, and for kicks, they simplified MD4 collisions to the point where they can be calculated by hand).



作者:孤枕难眠海归商务 发贴, 来自【海归网】 http://www.haiguinet.com









相关主题
[教学] ZT: 这个教授的功夫还不够 海归酒吧 2006-3-30 周四, 10:36
【猎头职位】韩企IT领域 战略发展专员-要求日籍-薪酬open 海归职场 2008-7-09 周三, 18:54
【转个趣味科学】美国教授研究发现:好色男人从脸形就能看出 海归酒吧 2011-8-17 周三, 11:28
国际医学界31位教授发公开信支持肖传国 海归商务 2010-10-03 周日, 14:14
北京【电信领域BI海外职位】-东南亚等地机会!英语好BI经验进来哦~~ 海归职场 2010-7-08 周四, 22:07
[转帖]西南政法大学75岁老教授赵长青为黎强案辩护词 生活风情 2011-6-17 周五, 13:29
ZT: 复旦大学财务系教授李若山的幽默 海归酒吧 2010-3-26 周五, 10:51
【本科留学】美国大学中国本科留学生激增 教授担心良莠不齐 海归主坛 2009-10-04 周日, 23:47

返回顶端
阅读会员资料 孤枕难眠离线  发送站内短信
显示文章:     
回复主题   printer-friendly view    海归论坛首页 -> 海归商务           焦点讨论 | 精华区 | 嘉宾沙龙 | 白领丽人沙龙 所有的时间均为 北京时间


 
论坛转跳:   
不能在本论坛发表新主题, 不能回复主题, 不能编辑自己的文章, 不能删除自己的文章, 不能发表投票, 您 不可以 发表活动帖子在本论坛, 不能添加附件不能下载文件, 
   热门标签 更多...
   论坛精华荟萃 更多...
   博客热门文章 更多...


海归网二次开发,based on phpbb
Copyright © 2005-2026 Haiguinet.com. All rights reserved.