<p>The <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> family is a U.S. federal standard published by NIST. Due to its complex design compared with <Emphasis FontCategory="SansSerif">SHA-1</Emphasis>, there is almost no progress in collision attacks on <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> after ASIACRYPT 2015. In this work, we retake this challenge and aim to significantly improve collision attacks on the <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> family. First, we observe from many existing attacks on <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> that the current advanced tool to search for <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> characteristics has reached its limits. Specifically, longer differential characteristics could not be found and collision attacks on more steps could not be reached. To overcome this obstacle, we adopt Liu et al.’s MILP-based method for signed differential characteristics published at EUROCRYPT 2023, and implement it with SAT/SMT for <Emphasis FontCategory="SansSerif">SHA-2</Emphasis>, where we also add more techniques to detect contradictions in <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> characteristics. This answers an open problem left in Liu et al.’s paper to apply the technique to <Emphasis FontCategory="SansSerif">SHA-2</Emphasis>. As a result, we successfully mount the first practical collision attack on 31-step <Emphasis FontCategory="SansSerif">SHA-256</Emphasis> and semi-free-start (SFS) collision attack on 39-step <Emphasis FontCategory="SansSerif">SHA-256</Emphasis>, respectively. In addition, we also report the first practical free-start (FS) collision attack on 40-step <Emphasis FontCategory="SansSerif">SHA-224</Emphasis>, improving the best theoretic 40-step attack of time complexity <InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(2^{110}\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mn>2</mn> <mn>110</mn> </msup> </math></EquationSource> </InlineEquation>. Moreover, we can also mount practical and theoretic collision attacks on 28-step and 31-step <Emphasis FontCategory="SansSerif">SHA-512</Emphasis>, respectively, which improve the best collision attack only reaching 27 steps of <Emphasis FontCategory="SansSerif">SHA-512</Emphasis> at ASIACRYPT 2015. Since we can search for longer differential characteristics, the collision attacks on <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> in the quantum setting are also improved. In summary, this paper achieves some notable progress in the analysis of <Emphasis FontCategory="SansSerif">SHA-2</Emphasis> after the major achievements made at EUROCRYPT 2013 and ASIACRYPT 2015.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

New Records in Collision Attacks on SHA-2

  • Yingxin Li,
  • Fukang Liu,
  • Gaoli Wang,
  • Haifeng Qian,
  • Xiaoyang Dong,
  • Siwei Sun,
  • Danping Shi

摘要

The SHA-2 family is a U.S. federal standard published by NIST. Due to its complex design compared with SHA-1, there is almost no progress in collision attacks on SHA-2 after ASIACRYPT 2015. In this work, we retake this challenge and aim to significantly improve collision attacks on the SHA-2 family. First, we observe from many existing attacks on SHA-2 that the current advanced tool to search for SHA-2 characteristics has reached its limits. Specifically, longer differential characteristics could not be found and collision attacks on more steps could not be reached. To overcome this obstacle, we adopt Liu et al.’s MILP-based method for signed differential characteristics published at EUROCRYPT 2023, and implement it with SAT/SMT for SHA-2, where we also add more techniques to detect contradictions in SHA-2 characteristics. This answers an open problem left in Liu et al.’s paper to apply the technique to SHA-2. As a result, we successfully mount the first practical collision attack on 31-step SHA-256 and semi-free-start (SFS) collision attack on 39-step SHA-256, respectively. In addition, we also report the first practical free-start (FS) collision attack on 40-step SHA-224, improving the best theoretic 40-step attack of time complexity \(2^{110}\) 2 110 . Moreover, we can also mount practical and theoretic collision attacks on 28-step and 31-step SHA-512, respectively, which improve the best collision attack only reaching 27 steps of SHA-512 at ASIACRYPT 2015. Since we can search for longer differential characteristics, the collision attacks on SHA-2 in the quantum setting are also improved. In summary, this paper achieves some notable progress in the analysis of SHA-2 after the major achievements made at EUROCRYPT 2013 and ASIACRYPT 2015.