Improved Resultant Attack Against Arithmetization-Oriented Primitives
Augustin Bariant, Aurélien Boeuf, Pierre Briaud, Maël Hostettler, Morten Øygarden, Håvard Raddum
Abstract
In the last decade, the introduction of advanced cryptographic protocols operating on large finite fields Fq has raised the need for efficient cryptographic primitives in this setting, commonly referred to as Arithmetization-Oriented (AO). The cryptanalysis of AO hash functions is essentially done through the study of the CICO problem on the underlying permutation. On several AO hash functions relying on S-boxes with low degree inverse, two recent works at Crypto 2024 and Asiacrypt 2024 managed to solve the CICO problem much more efficiently than traditional Gröbner basis methods, using respectively advanced Gröbner basis techniques and resultants. In this paper, we propose an attack framework based on resultants that applies to a wide range of AO permutations and improves significantly upon these two recent works. Our improvements mainly come from an efficient reduction procedure that we propose and rigorously analyze, taking advantage of fast multivariate multiplication. We present the most efficient attacks on Griffin, Arion, Anemoi, and Rescue. We show that most variants of Griffin, Arion and Anemoi fail to reach the claimed security level. For the first time, we successfully break a parameter set of Rescue, namely its 512-bit security variant. The presented theory and complexity estimates are backed up with experimental attacks. Notably, we practically find CICO solutions for 8 out of 10 rounds of Griffin, 11 out of 21 rounds of Anemoi, 6 out of 18 rounds of Rescue, improving by respectively 1, 3 and 1 rounds on the previous best practical attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d31d808-a570-4a62-a6ed-4defd00ff962Builds on4
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy et al.USENIX Security 2021 · 410 citations
- Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof SystemsTim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder et al.CRYPTO 2020 · 60 citations
- Horst Meets Fluid-SPN: Griffin for Zero-Knowledge ApplicationsLorenzo Grassi, Yonglin Hao, Christian Rechberger, Markus Schofnegger et al.CRYPTO 2023 · 38 citations
- The Algebraic FreeLunch: Efficient Gröbner Basis Attacks Against Arithmetization-Oriented PrimitivesAugustin Bariant, Aurélien Boeuf, Axel Lemoine, Irati Manterola Ayala et al.CRYPTO 2024 · 17 citations
Related papers
- New Design Techniques for Efficient Arithmetization-Oriented Hash Functions: ttAnemoi Permutations and ttJive Compression ModeClémence Bouvier, Pierre Briaud, Pyrros Chaidos, Léo Perrin et al.CRYPTO 2023 · 37 citations
- Gröbner Basis Cryptanalysis of AnemoiLuca Campa, Arnab RoyEUROCRYPT 2025 · 1 citation
- Boosting Efficiency and Security in Arithmetization-Oriented Hashing for Zero-Knowledge Proof SystemsElena Andreeva, Rishiraj Bhattacharyya, Arnab Roy, Stefano TrevisaniUSENIX Security 2026
- Graeffe-Based Attacks on Poseidon and NTT Lower BoundsZiyu Zhao, Antonio Sanso, Giuseppe Vitto, Jintai DingCRYPTO 2026 · 2 citations
- Coefficient Grouping: Breaking Chaghri and MoreFukang Liu, Ravi Anand, Libo Wang, Willi Meier et al.EUROCRYPT 2023 · 24 citations
