Lune

CRYPTO2026顶会

Pushing the Limit of Memory-Efficient Collision Attack Framework for SHA-2

Yingxin Li, Fukang Liu, Gaoli Wang, Jiali Shi

2026年份

摘要

The SHA-2 family hash is standardized by NIST and mainly includes two variants, SHA-256 and SHA-512. Due to its widespread deployment, its security has attracted continuous attention from various parties. Although Li et al. have developed open-source SAT/SMT-based tools and proposed new memory-efficient collision attack frameworks for SHA-2 in recent two years, practical collision attacks are only achieved for 31-step SHA-256 and 29-step SHA-512, respectively. To push the limit of such an attack framework for SHA-2, we carefully investigate existing strategies to choose message differences used in 38/39-step semi-free-start collision attacks. We found that by selecting message words (W4+i,…,W8+i,W12+i,W13+i,W20+i,W22+i)0≤i≤3(W_{4+i}, \ldots, W_{8+i}, W_{12+i}, W_{13+i}, W_{20+i}, W_{22+i})_{0\leq i \leq 3} to inject differences, and employing the open-source SAT/SMT-based automated tools to search for the corresponding differential characteristics, notable improvement can be achieved for practical and theoretical collision attacks. Specifically, the first practical collision attacks on 35-step SHA-256 and SHA-512 can be achieved for i=0i=0, improving the best practical collision attacks on SHA-256 and SHA-512 by 4 and 6 steps, respectively. When i∈{1,2}i\in\{1,2\}, theoretical collision attacks on both SHA-256 and SHA-512 can reach up to 36/37 steps. We have also tried collision attack up to 38 steps by setting i=3i=3, but the uncontrolled differential probability is too low to be used for effective attacks.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get b6c9176a-f79f-4b3b-974c-158f88999669

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖