Triangulating Rebound Attack on AES-like Hashing
Xiaoyang Dong, Jian Guo, Shun Li, Phuong Pham
Abstract
The rebound attack was introduced by Mendel et al. at FSE 2009 to fulfill a heavy middle round of a differential path for free, utilizing the degree of freedom from states. The inbound phase was extended to 2 rounds by the Super-Sbox technique invented by Lamberger et al. at ASIACRYPT 2009 and Gilbert and Peyrin at FSE 2010. In ASI-ACRYPT 2010, Sasaki et al. further reduced the requirement of memory by introducing the non-full-active Super-Sbox. In this paper, we further develop this line of research by introducing Super-Inbound, which is able to connect multiple 1-round or 2-round (non-full-active) Super-Sbox inbound phases by utilizing fully the degrees of freedom from both states and key, yet without the use of large memory. This essentially extends the inbound phase by up to 3 rounds. We applied this technique to find classic or quantum collisions on several AES-like hash functions, and improved the attacked round number by 1 to 5 in targets including AES-128 and SKINNY hashing modes, Saturnin-Hash, and Grøstl-512. To demonstrate the correctness of our attacks, the semi-free-start collision on 6-round AES-128-MMO/MP with estimated time complexity 2 24 in classical setting was implemented and an example pair was found instantly on a standard PC.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 67edf1a3-1e73-4415-8a79-8a88639adca9Builds on8
- MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferMarcel Keller, Emmanuela Orsini, Peter SchollCCS 2016 · 487 citations
- Efficient and Secure Multiparty Computation from Fixed-Key Block CiphersChun Guo, Jonathan Katz, Xiao Wang, Yu YuS&P 2020 · 96 citations
- Finding Hash Collisions with Quantum Computers by Using Differential Trails with Smaller Probability than Birthday BoundAkinori Hosoyamada, Yu SasakiEUROCRYPT 2020 · 78 citations
- Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage AttacksXiaoyang Dong, Jialiang Hua, Siwei Sun, Zheng Li et al.CRYPTO 2021 · 54 citations
- Quantum Collision Attacks on Reduced SHA-256 and SHA-512Akinori Hosoyamada, Yu SasakiCRYPTO 2021 · 52 citations
Related papers
- Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on AES-256 in DM Hash ModeLiyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang DongCRYPTO 2026
- Guess-and-Determine Rebound: Applications to Key Collisions on AESLingyue Qin, Wenquan Bi, Xiaoyang DongCRYPTO 2025 · 1 citation
- Diving Deep into the Preimage Security of AES-Like HashingShiyao Chen, Jian Guo, Eik List, Danping Shi et al.EUROCRYPT 2024 · 11 citations
- Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like HashingZhenzhen Bao, Xiaoyang Dong, Jian Guo, Zheng Li et al.EUROCRYPT 2021 · 47 citations
- Triangulating Meet-in-the-Middle AttackBoxin Zhao, Qingliang Hou, Lingyue Qin, Xiaoyang DongCRYPTO 2025 · 1 citation
