Analysis of RIPEMD-160: New Collision Attacks and Finding Characteristics with MILP
Fukang Liu, Gaoli Wang, Santanu Sarkar, Ravi Anand, Willi Meier, Yingxin Li, Takanori Isobe
Abstract
The hash function RIPEMD-160 is an ISO/IEC standard and is being used to generate the bitcoin address together with SHA-256. Despite the fact that many hash functions in the MD-SHA hash family have been broken, RIPEMD-160 remains secure and the best collision attack could only reach up to 34 out of 80 rounds, which was published at CRYPTO 2019. In this paper, we propose a new collision attack on RIPEMD-160 that can reach up to 36 rounds with time complexity . This new attack is facilitated by a new strategy to choose the message differences and new techniques to simultaneously handle the differential conditions on both branches. Moreover, different from all the previous work on RIPEMD-160, we utilize a MILP-based method to search for differential characteristics, where we construct a model to accurately describe the signed difference transitions through its round function. As far as we know, this is the first model targeting the signed difference transitions for the MD-SHA hash family. Indeed, we are more motivated to design this model by the fact that many automatic tools to search for such differential characteristics are not publicly available and implementing them from scratch is too time-consuming and difficult. Hence, we expect that this can be an alternative easy tool for future research, which only requires to write down some simple linear inequalities.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 39a85eee-6b20-412c-9735-602d179ca3afCited by top-tier papers1
Ask how each one uses itRelated papers
- Pushing the Limit of Memory-Efficient Collision Attack Framework for SHA-2Yingxin Li, Fukang Liu, Gaoli Wang, Jiali ShiCRYPTO 2026
- Collision Attacks on SHA-256 up to 37 Steps with Improved Trail SearchZhuolong Zhang, Muzhou Li, Lei Gao, Meiqin WangEUROCRYPT 2026 · 1 citation
- New Collision Attacks on Round-Reduced SHA-512Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian et al.CRYPTO 2025 · 4 citations
- Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5Jian Guo, Haoran Li, Meicheng Liu, Shichang Wang et al.EUROCRYPT 2026
- Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like HashingZhenzhen Bao, Xiaoyang Dong, Jian Guo, Zheng Li et al.EUROCRYPT 2021 · 47 citations
