Pushing the Limit of Memory-Efficient Collision Attack Framework for SHA-2
Yingxin Li, Fukang Liu, Gaoli Wang, Jiali Shi
Abstract
The SHA-2 family hash is standardized by NIST and mainly includes two variants, SHA-256 and SHA-512. Due to its widespread deployment, its security has attracted continuous attention from various parties. Although Li et al. have developed open-source SAT/SMT-based tools and proposed new memory-efficient collision attack frameworks for SHA-2 in recent two years, practical collision attacks are only achieved for 31-step SHA-256 and 29-step SHA-512, respectively. To push the limit of such an attack framework for SHA-2, we carefully investigate existing strategies to choose message differences used in 38/39-step semi-free-start collision attacks. We found that by selecting message words to inject differences, and employing the open-source SAT/SMT-based automated tools to search for the corresponding differential characteristics, notable improvement can be achieved for practical and theoretical collision attacks. Specifically, the first practical collision attacks on 35-step SHA-256 and SHA-512 can be achieved for , improving the best practical collision attacks on SHA-256 and SHA-512 by 4 and 6 steps, respectively. When , theoretical collision attacks on both SHA-256 and SHA-512 can reach up to 36/37 steps. We have also tried collision attack up to 38 steps by setting , but the uncontrolled differential probability is too low to be used for effective attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b6c9176a-f79f-4b3b-974c-158f88999669Related papers
- New Records in Collision Attacks on SHA-2Yingxin Li, Fukang Liu, Gaoli WangEUROCRYPT 2024 · 14 citations
- Quantum Collision Attacks on Reduced SHA-256 and SHA-512Akinori Hosoyamada, Yu SasakiCRYPTO 2021 · 52 citations
- Collision Attacks on SHA-256 up to 37 Steps with Improved Trail SearchZhuolong Zhang, Muzhou Li, Lei Gao, Meiqin WangEUROCRYPT 2026 · 1 citation
- New Collision Attacks on Round-Reduced SHA-512Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian et al.CRYPTO 2025 · 4 citations
- Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5Jian Guo, Haoran Li, Meicheng Liu, Shichang Wang et al.EUROCRYPT 2026
