Quantum Collision Attacks on Reduced SHA-256 and SHA-512
Akinori Hosoyamada, Yu Sasaki
Abstract
In this paper, we study dedicated quantum collision attacks on SHA-256 and SHA-512 for the first time. The attacks reach 38 and 39 steps, respectively, which significantly improve the classical attacks for 31 and 27 steps. Both attacks adopt the framework of the previous work that converts many semi-free-start collisions into a 2-block collision, and are faster than the generic attack in the cost metric of time-space tradeoff. We observe that the number of required semi-free-start collisions can be reduced in the quantum setting, which allows us to convert the previous classical 38 and 39 step semi-free-start collisions into a collision. The idea behind our attacks is simple and will also be applicable to other cryptographic hash functions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4923c8aa-03b4-437e-b466-6d29e45bdfb8Cited by top-tier papers3
- Beyond Quadratic Speedups in Quantum Attacks on Symmetric SchemesXavier Bonnetain, André Schrottenloher, Ferdinand SibleyrasEUROCRYPT 2022 · 32 citations
- Simplified MITM Modeling for Permutations: New (Quantum) AttacksAndré Schrottenloher, Marc StevensCRYPTO 2022 · 31 citations
- Triangulating Rebound Attack on AES-like HashingXiaoyang Dong, Jian Guo, Shun Li, Phuong PhamCRYPTO 2022 · 19 citations
Builds on2
- Finding Hash Collisions with Quantum Computers by Using Differential Trails with Smaller Probability than Birthday BoundAkinori Hosoyamada, Yu SasakiEUROCRYPT 2020 · 78 citations
- SHA-1 is a Shambles: First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of TrustGaëtan Leurent, Thomas PeyrinUSENIX Security 2020
Related papers
- Pushing the Limit of Memory-Efficient Collision Attack Framework for SHA-2Yingxin Li, Fukang Liu, Gaoli Wang, Jiali ShiCRYPTO 2026
- New Records in Collision Attacks on SHA-2Yingxin Li, Fukang Liu, Gaoli WangEUROCRYPT 2024 · 14 citations
- Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on AES-256 in DM Hash ModeLiyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang DongCRYPTO 2026
- Collision Attacks on SHA-256 up to 37 Steps with Improved Trail SearchZhuolong Zhang, Muzhou Li, Lei Gao, Meiqin WangEUROCRYPT 2026 · 1 citation
- New Collision Attacks on Round-Reduced SHA-512Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian et al.CRYPTO 2025 · 4 citations
