Paper 2026/2031

Mind Small Integers in MDS Matrix: Collision Attacks on Round-Reduced Reinforced Concrete

Jiamin Cui, School of Cyber Science and Technology, Shandong University, Qingdao, Shandong, China, State Key Laboratory of Cryptography and Digital Economy Security, Shandong University, Qingdao, 266237, Shandong, China, Key Laboratory of Cryptologic Technology and Information Security, Ministry of Education, Shandong University, Jinan, China
Fukang Liu, Institute of Science Tokyo, Tokyo, Japan
Jianqiang Ni, Shanghai Key Laboratory of Trustworthy Computing, Software Engineering Institute, East China Normal University, Shanghai, China
Willi Meier, University of Applied Sciences and Arts Northwestern Switzerland, Windisch, Switzerland
Abstract

The rapid advancement of Zero-Knowledge Proofs (ZKP) has motivated the design of ZK-friendly hash functions. A relatively new design strategy for ZK-friendly hash functions is using the composition of small look-up tables (LUTs) to build a nonlinear transform (called Bars layer) over a large prime field $\mathbb{F}_p$. This not only improves the plain performance but also enhances its security against algebraic attacks since the Bars layer is equivalent to a complex and high-degree polynomial over $\mathbb{F}_p$. This design strategy was first proposed at CCS 2022 for the ZK-friendly hash function Reinforced Concrete. However, there has been no third-party collion attacks of Reinforced Concrete since then, and all existing attacks on such LUT-based ZK-friendly ciphers like Tip5, Monolith and Skyscraper mainly exploit the differential or linear properties of Bars. In this paper, we demonstrate that the Bars layer surrounded by MDS matrices (called Concrete layers) with small integers, i.e., $Concrete\circ Bars\circ Concrete$, might lead to weaker differential properties of the round function. This key observation leads to a novel collision attack on 4.5 out of 7 rounds of Reinforced Concrete, successfully bypassing the Bars layer as well as the subsequent Concrete layer and power-map-based nonlinear layer (called Bricks layer). The attack is verified by providing a practical collision for 3.5-round Reinforced Concrete where the last 4 layers are $Bricks \circ Concrete \circ Bars\circ Concrete$. Furthermore, we provide constructive countermeasures by designing an algorithm to generate an improved Concrete layer that thwarts this specific attack while preserving the efficiency of the original design. Finally, we also applied our framework to Tip5 but found that its MDS matrix can effectively prevent this attack. This is the first time to exploit the weak combination of Bars layer and Concrete layer to mount efficient attacks on LUT-based ZK-friendly hash functions. We believe that it sheds new insight into the security of these hash functions.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
ZK-friendlyHash functionsLookup tableMDS matrixCollision attacksReinforced Concrete
Contact author(s)
cuijiamin @ sdu edu cn
liufukangs @ gmail com
jianqiangni0213 @ 163 com
willimeier48 @ gmail com
History
2026-09-17: approved
2026-09-14: received
See all versions
Short URL
https://ia.cr/2026/2031
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2031,
      author = {Jiamin Cui and Fukang Liu and Jianqiang Ni and Willi Meier},
      title = {Mind Small Integers in {MDS} Matrix: Collision Attacks on Round-Reduced Reinforced Concrete},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2031},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2031}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.