Cryptanalysis of reduced version of HAVAL

The first published cryptanalysis results of the HAVAL hash function are presented. A new approach is introduced which enables the computation of a collision for the 256 output bits of the last two rounds of three round HAVAL to be carried out in less than 5 s on a 200 MHz Pentium Pro.