Meet-in-the-Middle Preimage Attacks on Sponge-Based Hashing
Lingyue Qin, Jialiang Hua, Xiaoyang Dong, Hailun Yan, Xiaoyun Wang
Abstract
The Meet-in-the-Middle (MitM) attack has been widely applied to preimage attacks on Merkle-Damgrd (MD) hashing. In this paper, we introduce a generic framework of the MitM attack on sponge-based hashing. We find certain bit conditions can significantly reduce the diffusion of the unknown bits and lead to longer MitM characteristics. To find good or optimal configurations of MitM attacks, e.g., the bit conditions, the neutral sets, and the matching points, we introduce the bit-level MILP-based automatic tools on Keccak, Ascon and Xoodyak. To reduce the scale of bit-level models and make them solvable in reasonable time, a series of properties of the targeted hashing are considered in the modelling, such as the linear structure and CP-kernel for Keccak, the Boolean expression of Sbox for Ascon. Finally, we give an improved 4-round preimage attack on Keccak-512/SHA3, and break a nearly 10 years’ cryptanalysis record. We also give the first preimage attacks on 3-/4-round Ascon-XOF and 3-round Xoodyak-XOF.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cf6e4415-a2c4-4ad8-bfbb-ed21e2b427d5Cited by top-tier papers1
Ask how each one uses itRelated papers
- Generic MitM Attack Frameworks on Sponge ConstructionsXiaoyang Dong, Boxin Zhao, Lingyue Qin, Qingliang Hou et al.CRYPTO 2024 · 10 citations
- Simplified MITM Modeling for Permutations: New (Quantum) AttacksAndré Schrottenloher, Marc StevensCRYPTO 2022 · 31 citations
- Preimage Attacks on up to 5 Rounds of SHA-3 Using Internal DifferentialsZhongyi Zhang, Chengan Hou, Meicheng LiuEUROCRYPT 2025 · 1 citation
- Dual-Syncopation Meet-in-the-Middle Attacks: New Results on SHA-2 and MD5Jian Guo, Haoran Li, Meicheng Liu, Shichang Wang et al.EUROCRYPT 2026
- Diving Deep into the Preimage Security of AES-Like HashingShiyao Chen, Jian Guo, Eik List, Danping Shi et al.EUROCRYPT 2024 · 11 citations
