Permutation-Based Hashing with Stronger (Second) Preimage Resistance
Siwei Sun, Shun Li, Zhiyu Zhang, Charlotte Lefevre, Bart Mennink, Zhen Qin, Dengguo Feng
Abstract
The sponge is a popular construction of hash function design. It operates with a -bit permutation on a -bit state, that is split into a -bit inner part and an -bit outer part. However, the security bounds of the sponge are most often dominated by the capacity : if the length of the digest is bits, the construction tightly achieves -bit collision resistance, -bit second preimage resistance, and -bit preimage resistance. Here, it is noteworthy that the generic attacks matching the preimage and second preimage bounds make use of the inverse of the permutation.
We demonstrate that, by a relatively simple adjustment, significantly improved preimage and second preimage resistance can be achieved. In detail, we first present the SPONGE-DM construction, that differs from the sponge by evaluating the permutation during absorption in a Davies-Meyer mode. This construction generically achieves -bit collision resistance as the sponge does, but -bit preimage resistance and -bit second preimage resistance, where is the maximum size of the first preimage in blocks. Next, we investigate how improved security can be achieved with a smaller feed-forward, and we present the SPONGE-EDM family of functions, indexed by a parameter . These functions replace the permutation during absorption in the sponge by an Encrypted Davies-Meyer mode, but with only bits of feed-forward. For , comparable bounds as for SPONGE-DM are obtained, and these bounds gradually decrease to the original sponge bounds for decreasing values of .
We present various instantiations of SPONGE-DM and SPONGE-EDM using the Keccak and Ascon permutations, and concretely demonstrate the immediate security and performance gains of these instances. For example, one can achieve up to -bit preimage and second preimage resistance using the -bit Keccak permutation (rather than 1600-bit in SHA-3), and likewise, one can use the -bit Keccak permutation to easily achieve up to -bit preimage and second preimage resistance (therewith properly fitting within the recently announced Chinese call for a new generation of cryptographic algorithms). Finally, we show the benefits of using these instantiations in the context of hash-based signature schemes whose security relies solely on the (second) preimage resistance of the underlying hash functions (such as Ascon-Sign).
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Permutation-Based Hash from Non-Idealized Assumptions: Adding Feed-Forward to SpongeChun Guo, Kai Hu, Shuntian Jiang, Yanhong Fan et al.CRYPTO 2026
- Tight Preimage Resistance of the Sponge ConstructionCharlotte Lefevre, Bart MenninkCRYPTO 2022 · 15 citations
- Generic MitM Attack Frameworks on Sponge ConstructionsXiaoyang Dong, Boxin Zhao, Lingyue Qin, Qingliang Hou et al.CRYPTO 2024 · 10 citations
- Time-Space Tradeoffs for Sponge Hashing: Attacks and Limitations for Short CollisionsCody Freitag, Ashrujit Ghoshal, Ilan KomargodskiCRYPTO 2022 · 9 citations
- The Sponge Is Quantum IndifferentiableGorjan Alagic, Joseph Carolan, Christian Majenz, Saliha TokatFOCS 2025 · 6 citations
