Internet Engineering Task Force (IETF) S. Turner Request for Comments: 6151 IECA Updates: 1321, 2104 L. Chen Category: Informational NIST ISSN: 2070-1721 March 2011Updated Security Considerations for the MD5 Message-Digest and the HMAC-MD5 Algorithms
Turner & Chen Informational [Page 1]
RFC 6151 MD5 and HMAC-MD5 Security Considerations March 2011 1. IntroductionMD5 [MD5] is a message digest algorithm that takes as input a message of arbitrary length and produces as output a 128-bit "fingerprint" or "message digest" of the input. The published attacks against MD5 show that it is not prudent to use MD5 when collision resistance is required. This document replaces the security considerations in RFC 1321 [MD5].
2. Security Considerations
MD5 was published in 1992 as an Informational RFC. Since that time, MD5 has been extensively studied and new cryptographic attacks have been discovered. Message digest algorithms are designed to provide collision, pre-image, and second pre-image resistance. In addition, message digest algorithms are used with a shared secret value for message authentication in HMAC, and in this context, some people may find the guidance for key lengths and algorithm strengths in [SP800-57] and [SP800-131] useful.
Turner & Chen Informational [Page 2]
RFC 6151 MD5 and HMAC-MD5 Security Considerations March 2011 2.1. Collision ResistancePseudo-collisions for the compress function of MD5 were first described in 1993 [denBBO1993]. In 1996, [DOB1995] demonstrated a collision pair for the MD5 compression function with a chosen initial value. The first paper that demonstrated two collision pairs for MD5 was published in 2004 [WFLY2004]. The detailed attack techniques for MD5 were published at EUROCRYPT 2005 [WAYU2005]. Since then, a lot of research results have been published to improve collision attacks on MD5. The attacks presented in [KLIM2006] can find MD5 collision in about one minute on a standard notebook PC (Intel Pentium, 1.6GHz). [STEV2007] claims that it takes 10 seconds or less on a 2.6Ghz Pentium4 to find collisions. In [STEV2007], [SLdeW2007], [SSALMOdeW2009], and [SLdeW2009], the collision attacks on MD5 were successfully applied to X.509 certificates.
2.2. Pre-Image and Second Pre-Image Resistance
Even though the best result can find a pre-image attack of MD5 faster than exhaustive search, as presented in [SAAO2009], the complexity 2^123.4 is still pretty high.
2.3. HMAC
The cryptanalysis of HMAC-MD5 is usually conducted together with NMAC (Nested MAC) since they are closely related. NMAC uses two independent keys K1 and K2 such that NMAC(K1, K2, M) = H(K1, H(K2, M), where K1 and K2 are used as secret initialization vectors (IVs) for hash function H(IV, M). If we re-write the HMAC equation using two secret IVs such that IV2 = H(K Xor ipad) and IV1 = H(K Xor opad), then HMAC(K, M) = NMAC(IV1, IV2, M). Here it is very important to notice that IV1 and IV2 are not independently selected.
Turner & Chen Informational [Page 3]
RFC 6151 MD5 and HMAC-MD5 Security Considerations March 2011
A EUROCRYPT 2009 paper presented a distinguishing attack on HMAC-MD5 [WYWZZ2009] without using related keys. It can distinguish an instantiation of HMAC with MD5 from an instantiation with a random function with 2^97 queries with probability 0.87. This is called distinguishing-H. Using the distinguishing attack, it can recover some bits of the intermediate status of the second block. However, as it is pointed out in [WYWZZ2009], it cannot be used to recover the (partial) inner key H(K Xor ipad). It is not obvious how the attack can be used to form a forgery attack either.
3. Acknowledgements
Obviously, we have to thank all the cryptographers who produced the results we refer to in this document. We'd also like to thank Wesley Eddy, Sam Hartman, Alfred Hoenes, Martin Rex, Benne de Weger, and Lloyd Wood for their comments.
4. Informative References
[AES-CMAC] Song, JH., Poovendran, R., Lee, J., and T. Iwata, "The
Turner & Chen Informational [Page 4]
RFC 6151 MD5 and HMAC-MD5 Security Considerations March 2011
[DOB1995] Dobbertin, H., "Cryptanalysis of MD5 Compress",
Turner & Chen Informational [Page 5]
RFC 6151 MD5 and HMAC-MD5 Security Considerations March 2011
[SSALMOdeW2009]
Turner & Chen Informational [Page 6]
RFC 6151 MD5 and HMAC-MD5 Security Considerations March 2011
Authors' Addresses