Collision Attacks on Hashing Modes of Areion
摘要
Areion is a family of wide-block permutations proposed at CHES 2023. For the security against differential attacks of Areion, the designers showed only upper bounds of the differential characteristic probability, which are derived from the lower bounds of the number of active S-boxes by a byte-wise search. In this paper, we obtain tighter bounds on differential characteristic probability of Areion by a bit-wise SAT-based search tool. We discover a new inherent property in the S-box layers for Areion permutation, which is overlooked by designers’ evaluation. This enables us to significantly update the bounds of differential probability. Furthermore, leveraging this new property with our SAT-based tool, we develop collision attacks on Areion-DM (Davies-Meyer) and Areion-MD (Merkle-Damgård) hashing modes. As a result, we demonstrate 4/6-round collision attacks on Areion256/512-DM, and 7-round semi-free-start collision on Areion-MD.