Tag Second-preimage Attack against π-cipher

The π-cipher is one of the candidates of the CAESAR competition. One of the advertised features of the π-cipher is tag second-preimage resistance: it should be hard to generate a message with a given tag, even for the legitimate key holder (insider attack). In this note, we show that the generalized birthday attack of Wagner gives a practical tag second-preimage attack against the π-cipher.

Data and Resources

Additional Info

Field Value
Source https://inria.hal.science/hal-00966794
Author Leurent, Gaëtan
Maintainer CCSD
Last Updated May 5, 2026, 20:11 (UTC)
Created May 5, 2026, 20:11 (UTC)
Identifier hal-00966794
Language en
Rights https://about.hal.science/hal-authorisation-v1/
contributor Security, Cryptology and Transmissions (SECRET) ; Inria Paris-Rocquencourt ; Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National de Recherche en Informatique et en Automatique (Inria)
creator Leurent, Gaëtan
date 2014-03-27T00:00:00
harvest_object_id 0e9dc957-03c4-45ca-884e-58c3bcbebc97
harvest_source_id 3374d638-d20b-4672-ba96-a23232d55657
harvest_source_title test moissonnage SELUNE
metadata_modified 2025-02-26T00:00:00
set_spec type:UNDEFINED