Bicliques for Preimages: Attacks on Skein-512 and the SHA-2 family

Dmitry Khovratovich and Christian Rechberger and Alexandra Savelieva

Abstract: We present the new concept of biclique as a tool for preimage attacks, which employs many powerful techniques from differential cryptanalysis of block ciphers and hash functions.

The new tool has proved to be widely applicable by inspiring many authors to publish new results of the full versions of AES, KASUMI, IDEA, Square, and others. In this paper, we demonstrate how our concept results in the first cryptanalysis of the Skein hash function, and describe an attack on the SHA-2 hash function with more rounds than before.

Date: received 31 May 2011, last revised 7 Feb 2012

