Evaluate the Security Margins of SHA-512, SHA-256and DHA-256 Against the Boomerang Attack

Hongbo Yu,Yonglin Hao,Dongxia Bai
DOI: https://doi.org/10.1007/s11432-015-5389-4
2016-01-01
Science China Information Sciences
Abstract:For an n-bit random permutation, there are three types of boomerang distinguishers, denoted as Type I, II and III, with generic complexities 2 n , 2 n/3 and 2 n/2 respectively. In this paper, we try to evaluate the security margins of three hash functions namely SHA-512, SHA-256 and DHA-256 against the boomerang attack.Firstly, we give a boomerang attack on 48-step SHA-512 with a practical complexity of 2 51 . The correctness of this attack is verified by providing a Type III boomerang quartet. Then, we extend the existing differential characteristics of the three hash functions to more rounds. We deduce the sufficient conditions and give thorough evaluations to the security margins as follows: Type I boomerang method can attack 54-step SHA-512, 51-step SHA-256 and 46-step DHA-256 with complexities 2 480 , 2 218 and 2 236 respectively. Type II boomerang method can attack 51-step SHA-512, 49-step SHA-256 and 43-step DHA-256 with complexities 2 158.50 , 2 72.91 and 2 74.50 respectively. Type III boomerang method can attack 52-step SHA-512, 50-step SHA-256 and 44-step DHA-256 with complexities 2 223.80 , 2 123.63 and 2 99.85 respectively.
What problem does this paper attempt to address?