Collision Attacks on SHA-256 up to 37 Steps with Improved Trail Search
Zhuolong Zhang, Muzhou Li, Lei Gao, Meiqin Wang
Abstract
As a NIST-standardized hash function, SHA-256 has been extensively analyzed in the context of collision attacks. Although Mendel et al. introduced the first 31-step collision attack at EUROCRYPT 2013, the number of attacked steps has not been increased for more than a decade. After a thorough review of existing attacks, we identify that progressing beyond 31 steps necessitates new local collisions in the message expansion. To date, such local collisions have been manually constructed, which is both time-consuming and technically challenging. Besides, even the latest automated models for searching signed differential trails fail to accurately account for the bit conditions imposed by Boolean functions, potentially overlooking high-quality trails. In this paper, we enhance the existing framework by overcoming these two limitations. Firstly, an automated tool that can efficiently identify high-quality local collisions is given following the main idea of EUROCRYPT 2013. Secondly, two new models of Boolean functions that can accurately capture bit conditions are introduced. Leveraging these improvements, we finally reach the first 37-step collision attack on SHA-256, extending the number of attacked steps by six, and this is the first such advancement in 12 years.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 717021dc-28ed-4834-9029-1199dc844b73Related papers
- Pushing the Limit of Memory-Efficient Collision Attack Framework for SHA-2Yingxin Li, Fukang Liu, Gaoli Wang, Jiali ShiCRYPTO 2026
- Quantum Collision Attacks on Reduced SHA-256 and SHA-512Akinori Hosoyamada, Yu SasakiCRYPTO 2021 · 52 citations
- New Records in Collision Attacks on SHA-2Yingxin Li, Fukang Liu, Gaoli WangEUROCRYPT 2024 · 14 citations
- Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5Jian Guo, Haoran Li, Meicheng Liu, Shichang Wang et al.EUROCRYPT 2026
- Analysis of RIPEMD-160: New Collision Attacks and Finding Characteristics with MILPFukang Liu, Gaoli Wang, Santanu Sarkar, Ravi Anand et al.EUROCRYPT 2023 · 13 citations
