New Collision Attacks on Round-Reduced SHA-512
摘要
The SHA-2 family primarily includes two versions, SHA-256 and SHA-512. Although a memory-efficient practical collision attack has been recently proposed for 31-step SHA-256 at ASIACRYPT 2024, the best practical collision attack on SHA-512 still only reaches 28 steps, and the best theoretic collision attack on 31-step SHA-512 has the time complexity of \(2^{97.3}\) . This is mainly due to the large state of SHA-512 compared with SHA-256, despite their structural similarity. To enhance the collision attacks on SHA-512, we propose a new local collision by injecting difference at the message words \((W_9, W_{10}, W_{14}, W_{17}, W_{19})\) , allowing us to achieve the first practical collision attack on 29 steps of SHA-512. Moreover, to improve the collision attack on 31-step SHA-512, we improve Liu et al.’s method to model the signed difference transition through Boolean functions, by introducing a novel model to capture the 2-bit conditions, which frequently occur in SHA-512 characteristics. In this way, we can further improve the 31-step SHA-512 characteristic and reduce the time complexity of the collision attack on 31-step SHA-512 from \(2^{97.3}\) to \(2^{85.5}\) .