Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage Attacks
Xiaoyang Dong, Jialiang Hua, Siwei Sun, Zheng Li, Xiaoyun Wang, Lei Hu
Abstract
At EUROCRYPT 2021, Bao et al. proposed an automatic method for systematically exploring the configuration space of meet-in-the-middle (MITM) preimage attacks. We further extend it into a constraint-based framework for finding exploitable MITM characteristics in the context of key-recovery and collision attacks by taking the subtle peculiarities of both scenarios into account. Moreover, to perform attacks based on MITM characteristics with nonlinear constrained neutral words, which have not been seen before, we present a procedure for deriving the solution spaces of neutral words without solving the corresponding nonlinear equations or increasing the overall time complexities of the attack. We apply our method to concrete symmetric-key primitives, including SKINNY, ForkSkinny, Romulus, Saturnin, Grostl, Whirlpool, and hashing modes with AES-256. As a result, we identify the first 23-round key-recovery attack on SKINNY-- and the first 24-round key-recovery attack on ForkSkinny-- in the single-key model. Moreover, improved (pseudo) preimage or collision attacks on round-reduced Whirlpool, Grostl, and hashing modes with AES-256 are obtained. In particular, employing the new representation of the AES key schedule due to Leurent and Pernot (EUROCRYPT 2021), we identify the first preimage attack on 10-round AES-256 hashing.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7ec733d4-d2f0-42e6-8001-b7f888168f1eCited by top-tier papers6
- Simplified MITM Modeling for Permutations: New (Quantum) AttacksAndré Schrottenloher, Marc StevensCRYPTO 2022 · 31 citations
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander et al.CRYPTO 2023 · 24 citations
- Superposition Meet-in-the-Middle Attacks: Updates on Fundamental Security of AES-like HashingZhenzhen Bao, Jian Guo, Danping Shi, Yi TuCRYPTO 2022 · 23 citations
- Triangulating Rebound Attack on AES-like HashingXiaoyang Dong, Jian Guo, Shun Li, Phuong PhamCRYPTO 2022 · 19 citations
- Improved Differential Meet-in-the-Middle CryptanalysisZahra Ahmadian, Akram Khalesi, Dounia M'foukh, Hossein Moghimi et al.EUROCRYPT 2024 · 14 citations
Related papers
- Diving Deep into the Preimage Security of AES-Like HashingShiyao Chen, Jian Guo, Eik List, Danping Shi et al.EUROCRYPT 2024 · 11 citations
- Triangulating Meet-in-the-Middle AttackBoxin Zhao, Qingliang Hou, Lingyue Qin, Xiaoyang DongCRYPTO 2025 · 1 citation
- Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like HashingZhenzhen Bao, Xiaoyang Dong, Jian Guo, Zheng Li et al.EUROCRYPT 2021 · 47 citations
- Meet-in-the-Middle Preimage Attacks on Sponge-Based HashingLingyue Qin, Jialiang Hua, Xiaoyang Dong, Hailun Yan et al.EUROCRYPT 2023 · 32 citations
- Exploiting Non-full Key Additions: Full-Fledged Automatic Demirci-Selçuk Meet-in-the-Middle Cryptanalysis of SKINNYDanping Shi, Siwei Sun, Ling Song, Lei Hu et al.EUROCRYPT 2023 · 9 citations
