Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on AES-256 in DM Hash Mode
Liyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang Dong
摘要
At CRYPTO 2025, Qin et al. introduced the guess-and-determine (GD) rebound attack, which integrates the guess-and-determine approach by Bouillaguet, Derbez, and Fouque and the rebound attack by Mendel et al. Taking the GD rebound as a building block, this paper introduces several classical and quantum models to convert the semi-free-start (SFS) collision attack or free-start (FS) collision attack into collision attacks on DM hashing mode with AES. As an application, the first full quantum collision attack on AES-256-DM is proposed. Despite numerous round-reduced quantum or classical attacks proposed against the three popular hash modes MMO/MP/DM with AES over the past two decades, this is the first full attack that targets one of the three fundamental security requirements: collision, (2nd) preimage resistance. Our full attack on AES-256-DM improves the best previous attack by Taiyama et al. at ASIACRYPT 2024 by 5 rounds. Besides, some improved results on AES-128-DM and AES-192-DM are also given, which have been verified partially or fully by experiments.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Triangulating Rebound Attack on AES-like HashingXiaoyang Dong, Jian Guo, Shun Li, Phuong PhamCRYPTO 2022 · 被引用 19 次
- Finding Hash Collisions with Quantum Computers by Using Differential Trails with Smaller Probability than Birthday BoundAkinori Hosoyamada, Yu SasakiEUROCRYPT 2020 · 被引用 78 次
- Quantum Collision Attacks on Reduced SHA-256 and SHA-512Akinori Hosoyamada, Yu SasakiCRYPTO 2021 · 被引用 52 次
- Guess-and-Determine Rebound: Applications to Key Collisions on AESLingyue Qin, Wenquan Bi, Xiaoyang DongCRYPTO 2025 · 被引用 1 次
- Generic MitM Attack Frameworks on Sponge ConstructionsXiaoyang Dong, Boxin Zhao, Lingyue Qin, Qingliang Hou 等CRYPTO 2024 · 被引用 10 次
