Triangulating Rebound Attack on AES-like Hashing
Xiaoyang Dong, Jian Guo, Shun Li, Phuong Pham
摘要
The rebound attack was introduced by Mendel et al. at FSE 2009 to fulfill a heavy middle round of a differential path for free, utilizing the degree of freedom from states. The inbound phase was extended to 2 rounds by the Super-Sbox technique invented by Lamberger et al. at ASIACRYPT 2009 and Gilbert and Peyrin at FSE 2010. In ASI-ACRYPT 2010, Sasaki et al. further reduced the requirement of memory by introducing the non-full-active Super-Sbox. In this paper, we further develop this line of research by introducing Super-Inbound, which is able to connect multiple 1-round or 2-round (non-full-active) Super-Sbox inbound phases by utilizing fully the degrees of freedom from both states and key, yet without the use of large memory. This essentially extends the inbound phase by up to 3 rounds. We applied this technique to find classic or quantum collisions on several AES-like hash functions, and improved the attacked round number by 1 to 5 in targets including AES-128 and SKINNY hashing modes, Saturnin-Hash, and Grøstl-512. To demonstrate the correctness of our attacks, the semi-free-start collision on 6-round AES-128-MMO/MP with estimated time complexity 2 24 in classical setting was implemented and an example pair was found instantly on a standard PC.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferMarcel Keller, Emmanuela Orsini, Peter SchollCCS 2016 · 被引用 487 次
- Efficient and Secure Multiparty Computation from Fixed-Key Block CiphersChun Guo, Jonathan Katz, Xiao Wang, Yu YuS&P 2020 · 被引用 96 次
- Finding Hash Collisions with Quantum Computers by Using Differential Trails with Smaller Probability than Birthday BoundAkinori Hosoyamada, Yu SasakiEUROCRYPT 2020 · 被引用 78 次
- Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage AttacksXiaoyang Dong, Jialiang Hua, Siwei Sun, Zheng Li 等CRYPTO 2021 · 被引用 54 次
- Quantum Collision Attacks on Reduced SHA-256 and SHA-512Akinori Hosoyamada, Yu SasakiCRYPTO 2021 · 被引用 52 次
相关 Paper
- Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on AES-256 in DM Hash ModeLiyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang DongCRYPTO 2026
- Guess-and-Determine Rebound: Applications to Key Collisions on AESLingyue Qin, Wenquan Bi, Xiaoyang DongCRYPTO 2025 · 被引用 1 次
- Diving Deep into the Preimage Security of AES-Like HashingShiyao Chen, Jian Guo, Eik List, Danping Shi 等EUROCRYPT 2024 · 被引用 11 次
- Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like HashingZhenzhen Bao, Xiaoyang Dong, Jian Guo, Zheng Li 等EUROCRYPT 2021 · 被引用 47 次
- Triangulating Meet-in-the-Middle AttackBoxin Zhao, Qingliang Hou, Lingyue Qin, Xiaoyang DongCRYPTO 2025 · 被引用 1 次
