Lune

CRYPTO2026Top-tier venue

Permutation-Based Hashing with Stronger (Second) Preimage Resistance

Siwei Sun, Shun Li, Zhiyu Zhang, Charlotte Lefevre, Bart Mennink, Zhen Qin, Dengguo Feng

2026Year

Abstract

The sponge is a popular construction of hash function design. It operates with a bb-bit permutation on a bb-bit state, that is split into a cc-bit inner part and an rr-bit outer part. However, the security bounds of the sponge are most often dominated by the capacity cc: if the length of the digest is nn bits, the construction tightly achieves min⁡{n/2,c/2}\min\{n/2,c/2\}-bit collision resistance, min⁡{n,c/2}\min\{n,c/2\}-bit second preimage resistance, and min⁡{n,max⁡{n−r,c/2}}\min\{n,\max\{n-r,c/2\}\}-bit preimage resistance. Here, it is noteworthy that the generic attacks matching the preimage and second preimage bounds make use of the inverse of the permutation.

We demonstrate that, by a relatively simple adjustment, significantly improved preimage and second preimage resistance can be achieved. In detail, we first present the SPONGE-DM construction, that differs from the sponge by evaluating the permutation during absorption in a Davies-Meyer mode. This construction generically achieves min⁡{n/2,c/2}\min\{n/2,c/2\}-bit collision resistance as the sponge does, but nn-bit preimage resistance and min⁡{n,c−log⁡2(α)}\min\{n,c-\log_2(\alpha)\}-bit second preimage resistance, where α\alpha is the maximum size of the first preimage in blocks. Next, we investigate how improved security can be achieved with a smaller feed-forward, and we present the SPONGE-EDMa^a family of functions, indexed by a parameter a∈{0,…,b}a\in\{0,\ldots,b\}. These functions replace the permutation during absorption in the sponge by an Encrypted Davies-Meyer mode, but with only aa bits of feed-forward. For a=ba=b, comparable bounds as for SPONGE-DM are obtained, and these bounds gradually decrease to the original sponge bounds for decreasing values of aa.

We present various instantiations of SPONGE-DM and SPONGE-EDMa^a using the Keccak and Ascon permutations, and concretely demonstrate the immediate security and performance gains of these instances. For example, one can achieve up to 512512-bit preimage and second preimage resistance using the 800800-bit Keccak permutation (rather than 1600-bit in SHA-3), and likewise, one can use the 16001600-bit Keccak permutation to easily achieve up to 10241024-bit preimage and second preimage resistance (therewith properly fitting within the recently announced Chinese call for a new generation of cryptographic algorithms). Finally, we show the benefits of using these instantiations in the context of hash-based signature schemes whose security relies solely on the (second) preimage resistance of the underlying hash functions (such as Ascon-Sign).

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines