Paper 2026/1050
Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on AES-256 in DM Hash Mode
Abstract
At CRYPTO 2025, Qin et al. introduced the guess-and-determine (GD) rebound attack, which integrates the guess-and-determine approach by Bouillaguet, Derbez, and Fouque and the rebound attack by Mendel et al. Taking the GD rebound as a building block, this paper introduces several classical and quantum models to convert the semi-free-start (SFS) collision attack or free-start (FS) collision attack into collision attacks on DM hashing mode with AES. As an application, the first full quantum collision attack on AES-256-DM is proposed. Despite numerous round-reduced quantum or classical attacks proposed against the three popular hash modes MMO/MP/DM with AES over the past two decades, this is the first full attack that targets one of the three fundamental security requirements: collision, (2nd) preimage resistance. Our full attack on AES-256-DM improves the best previous attack by Taiyama et al. at ASIACRYPT 2024 by 5 rounds. Besides, some improved results on AES-128-DM and AES-192-DM are also given, which have been verified partially or fully by experiments.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- A major revision of an IACR publication in CRYPTO 2026
- Keywords
- Rebound AttackGuess-and-DetermineAES-256Quantum Attack
- Contact author(s)
-
tangly22 @ mails tsinghua edu cn
qinly @ tsinghua edu cn
seventeenhsq @ gmail com
xiaoyangdong @ tsinghua edu cn - History
- 2026-05-28: last of 3 revisions
- 2026-05-25: received
- See all versions
- Short URL
- https://ia.cr/2026/1050
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1050,
author = {Liyuan Tang and Lingyue Qin and Shiqi Hou and Xiaoyang Dong},
title = {Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on {AES}-256 in {DM} Hash Mode},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1050},
year = {2026},
url = {https://eprint.iacr.org/2026/1050}
}