Permutation-Based Hashing with Stronger (Second) Preimage Resistance
Siwei Sun, Shun Li, Zhiyu Zhang, Charlotte Lefevre, Bart Mennink, Zhen Qin, Dengguo Feng
摘要
The sponge is a popular construction of hash function design. It operates with a -bit permutation on a -bit state, that is split into a -bit inner part and an -bit outer part. However, the security bounds of the sponge are most often dominated by the capacity : if the length of the digest is bits, the construction tightly achieves -bit collision resistance, -bit second preimage resistance, and -bit preimage resistance. Here, it is noteworthy that the generic attacks matching the preimage and second preimage bounds make use of the inverse of the permutation.
We demonstrate that, by a relatively simple adjustment, significantly improved preimage and second preimage resistance can be achieved. In detail, we first present the SPONGE-DM construction, that differs from the sponge by evaluating the permutation during absorption in a Davies-Meyer mode. This construction generically achieves -bit collision resistance as the sponge does, but -bit preimage resistance and -bit second preimage resistance, where is the maximum size of the first preimage in blocks. Next, we investigate how improved security can be achieved with a smaller feed-forward, and we present the SPONGE-EDM family of functions, indexed by a parameter . These functions replace the permutation during absorption in the sponge by an Encrypted Davies-Meyer mode, but with only bits of feed-forward. For , comparable bounds as for SPONGE-DM are obtained, and these bounds gradually decrease to the original sponge bounds for decreasing values of .
We present various instantiations of SPONGE-DM and SPONGE-EDM using the Keccak and Ascon permutations, and concretely demonstrate the immediate security and performance gains of these instances. For example, one can achieve up to -bit preimage and second preimage resistance using the -bit Keccak permutation (rather than 1600-bit in SHA-3), and likewise, one can use the -bit Keccak permutation to easily achieve up to -bit preimage and second preimage resistance (therewith properly fitting within the recently announced Chinese call for a new generation of cryptographic algorithms). Finally, we show the benefits of using these instantiations in the context of hash-based signature schemes whose security relies solely on the (second) preimage resistance of the underlying hash functions (such as Ascon-Sign).
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Permutation-Based Hash from Non-Idealized Assumptions: Adding Feed-Forward to SpongeChun Guo, Kai Hu, Shuntian Jiang, Yanhong Fan 等CRYPTO 2026
- Tight Preimage Resistance of the Sponge ConstructionCharlotte Lefevre, Bart MenninkCRYPTO 2022 · 被引用 15 次
- Generic MitM Attack Frameworks on Sponge ConstructionsXiaoyang Dong, Boxin Zhao, Lingyue Qin, Qingliang Hou 等CRYPTO 2024 · 被引用 10 次
- Time-Space Tradeoffs for Sponge Hashing: Attacks and Limitations for Short CollisionsCody Freitag, Ashrujit Ghoshal, Ilan KomargodskiCRYPTO 2022 · 被引用 9 次
- The Sponge Is Quantum IndifferentiableGorjan Alagic, Joseph Carolan, Christian Majenz, Saliha TokatFOCS 2025 · 被引用 6 次
