Paper 2025/1430

Practical Collision Attacks on Reduced-Round Xoodyak Hash Mode

Huina Li, Shanghai Jiao Tong University
Le He, Xidian University
Weidong Qiu, Shanghai Jiao Tong University
Abstract

\xoodyak is a finalist of the NIST lightweight cryptography competition, offering both keyed and hash modes. After several years of cryptanalysis, the largest number of \xoodyak hash rounds for which actual collisions was still in vacancy. To the best of our knowledge, one of the most powerful collision attacks on hash functions based on sponge construction is the differential-based attacks using the S-box linearization technique proposed by Qiao \etal (EUROCRYPT 2017). However, the linearization technique requires a large number of degrees of freedom, making it challenging to apply to \xoodyak with a small outer part. On the other hand, the constraint-input and constraint-output imposed on the differential trail of \xoodoo permutation make the exhaustive search for relatively high-probability differential trails in collision attacks extremely costly. In this paper, we present critical observations regarding \xoodoo round function, particularly focusing on its unique $\theta$ and $\chi$ operation. These properties can be leveraged to manually design specific differential trails, referred to as \textit{loop} trails. To efficiently find practical collisions for up to 3 rounds, we develop a SAT model based on these \textit{loop} trails. Finally, we present the first practical collision on 2 rounds and a practical semi-free-start collision on 3 rounds of \xoodyak hash mode. Besides, we improve Dong \etal's (CRYPTO 2024) collision attack on 3-round \xoodyak-\hash from $2^{125.23}$ to $2^{100.93}$ using several linearization strategies. Since we focus on the analysis on collisions during the message absorbing phase of the hash modes, our results are applicable to both \xoodyak-\hash and \xoodyak-\xof.

Note: Correct some typo errors.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. SAC 2025
Keywords
XoodyakXoodyak hash modeCollision attackSemi-free-start collision attack
Contact author(s)
lihuina @ sjtu edu cn
hele @ xidian edu cn
qiuwd @ sjtu edu cn
History
2025-08-18: last of 3 revisions
2025-08-06: received
See all versions
Short URL
https://ia.cr/2025/1430
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1430,
      author = {Huina Li and Le He and Weidong Qiu},
      title = {Practical Collision Attacks on Reduced-Round Xoodyak Hash Mode},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1430},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1430}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.