Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like Hashing
Zhenzhen Bao, Xiaoyang Dong, Jian Guo, Zheng Li, Danping Shi, Siwei Sun, Xiaoyun Wang
Abstract
The Meet-in-the-Middle (MITM) preimage attack is highly effective in breaking the preimage resistance of many hash functions, including but not limited to the full MD5, HAVAL, and Tiger, and reduced SHA-0/1/2. It was also shown to be a threat to hash functions built on block ciphers like AES by Sasaki in 2011. Recently, such attacks on AES hashing modes evolved from merely using the freedom of choosing the internal state to also exploiting the freedom of choosing the message state. However, detecting such attacks especially those evolved variants is difficult. In previous works, the search space of the configurations of such attacks is limited, such that manual analysis is practical, which results in sub-optimal solutions. In this paper, we remove artificial limitations in previous works, formulate the essential ideas of the construction of the attack in well-defined ways, and translate the problem of searching for the best attacks into optimization problems under constraints in Mixed-Integer-Linear-Programming (MILP) models. The MILP models capture a large solution space of valid attacks; and the objectives of the MILP models are attack configurations with the minimized computational complexity. With such MILP models and using the off-the-shelf solver, it is efficient to search for the best attacks exhaustively. As a result, we obtain the first attacks against the full (5-round) and an extended (5.5-round) version of Haraka-512 v2, and 8-round AES-128 hashing modes, as well as improved attacks covering more rounds of Haraka-256 v2 and other members of AES and Rijndael hashing modes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a62b97f5-8cfb-4d7a-bda0-cbe544214645Cited by top-tier papers5
- Simplified MITM Modeling for Permutations: New (Quantum) AttacksAndré Schrottenloher, Marc StevensCRYPTO 2022 · 31 citations
- Superposition Meet-in-the-Middle Attacks: Updates on Fundamental Security of AES-like HashingZhenzhen Bao, Jian Guo, Danping Shi, Yi TuCRYPTO 2022 · 23 citations
- Triangulating Rebound Attack on AES-like HashingXiaoyang Dong, Jian Guo, Shun Li, Phuong PhamCRYPTO 2022 · 19 citations
- ChiLow and ChiChi: New Constructions for Code EncryptionYanis Belkheyar, Patrick Derbez, Shibam Ghosh, Gregor Leander et al.EUROCRYPT 2025 · 7 citations
- The OCH Authenticated Encryption SchemeSanketh Menda, Mihir Bellare, Viet Tung Hoang, Julia Len et al.CCS 2025
Related papers
- Diving Deep into the Preimage Security of AES-Like HashingShiyao Chen, Jian Guo, Eik List, Danping Shi et al.EUROCRYPT 2024 · 11 citations
- Meet-in-the-Middle Preimage Attacks on Sponge-Based HashingLingyue Qin, Jialiang Hua, Xiaoyang Dong, Hailun Yan et al.EUROCRYPT 2023 · 32 citations
- Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5Jian Guo, Haoran Li, Meicheng Liu, Shichang Wang et al.EUROCRYPT 2026
- Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage AttacksXiaoyang Dong, Jialiang Hua, Siwei Sun, Zheng Li et al.CRYPTO 2021 · 54 citations
- Generic MitM Attack Frameworks on Sponge ConstructionsXiaoyang Dong, Boxin Zhao, Lingyue Qin, Qingliang Hou et al.CRYPTO 2024 · 10 citations
