In this paper, we study preimage resistance of the \(\texttt {SHA}\text {-} \texttt {3}\) standard. We propose a squeeze meet-in-the-middle attack as a new preimage attack method for the sponge functions. This attack combines the squeeze attack and meet-in-the-middle attack, and is implemented by internal differentials. We analyze the inverse operation of the \(\texttt {SHA}\text {-} \texttt {3}\) round function, and develop a new target internal differential algorithm as well as a linearization technique for the Sbox in the backward phase. In addition, we propose the concept of a value-difference distribution table (VDDT) to optimize the attack complexity. These techniques lead to faster preimage attacks on five (out of six) \(\texttt {SHA}\text {-} \texttt {3}\) functions reduced to 4 rounds, and also bring preimage attacks on 5 rounds of four \(\texttt {SHA}\text {-} \texttt {3}\) instances. The attack techniques are verified by performing practical preimage attack on a small variant of 4-round Keccak.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Preimage Attacks on up to 5 Rounds of SHA-3 Using Internal Differentials

  • Zhongyi Zhang,
  • Chengan Hou,
  • Meicheng Liu

摘要

In this paper, we study preimage resistance of the \(\texttt {SHA}\text {-} \texttt {3}\) standard. We propose a squeeze meet-in-the-middle attack as a new preimage attack method for the sponge functions. This attack combines the squeeze attack and meet-in-the-middle attack, and is implemented by internal differentials. We analyze the inverse operation of the \(\texttt {SHA}\text {-} \texttt {3}\) round function, and develop a new target internal differential algorithm as well as a linearization technique for the Sbox in the backward phase. In addition, we propose the concept of a value-difference distribution table (VDDT) to optimize the attack complexity. These techniques lead to faster preimage attacks on five (out of six) \(\texttt {SHA}\text {-} \texttt {3}\) functions reduced to 4 rounds, and also bring preimage attacks on 5 rounds of four \(\texttt {SHA}\text {-} \texttt {3}\) instances. The attack techniques are verified by performing practical preimage attack on a small variant of 4-round Keccak.