Internal differential structure: preimage attacks on up to 5-round Keccak
摘要
Internal differential cryptanalysis is introduced by Peyrin (Improved differential attacks for ECHO and Grøstl. In: Rabin T (ed) Advances in cryptology—CRYPTO 2010. LNCS, vol 6223. Springer, Berlin, pp 370–392, 2010. doi:10.1007/978-3-642-14623-7_20). It is generalized and firstly applied to collision attacks of round-reduced Keccak by Dinur et al. (Collision attacks on up to 5 rounds of SHA-3 using generalized internal differentials. In: Moriai S (ed) Fast software encryption. FSE 2013. LNCS, vol 8424. Springer, Berlin, pp 219–240, 2013. doi:10.1007/978-3-662-43933-3_12). Recently, internal differential cryptanalysis is further improved by Zhang et al., which brings better collision attacks. Inspired by their works, we propose a new technique named internal differential structure which is a framework of preimage attacks on round-reduced Keccak. The technique internal differential structure is a combination of two parts. The first part is a reversed characteristic from a fixed internal difference backward to the starting state with symmetric capacity. As for the second part, the internal difference keeps linear after 1.5 rounds until the last