Paper 2026/2152

Structural Weaknesses in 7 NGCC Submitted Hash Functions

Yufei Yuan, Institute of Software Chinese Academy of Sciences, University of Chinese Academy of Sciences
Ruichen Wu, Institute of Software Chinese Academy of Sciences, University of Chinese Academy of Sciences
Shanpeng Wei, Institute of Software Chinese Academy of Sciences, University of Chinese Academy of Sciences
Junxu Shen, Institute of Software Chinese Academy of Sciences, University of Chinese Academy of Sciences
Jinpeng Liu, Institute of Software Chinese Academy of Sciences
Yixin Zhang, Institute of Software Chinese Academy of Sciences, University of Chinese Academy of Sciences
Abstract

The Institute of Commercial Cryptography Standards (ICCS) launched the Next-generation Commercial Cryptographic Algorithms Program (NGCC) and invited worldwide comments on draft submission requirements and evaluation criteria for cryptographic hash algorithms. Our analysis of seven submitted hash functions gives the following results: - Message differences that cancel in every key injection give explicit collisions for all four fixed-output variants of \textbf{MoFang} and both XOF variants at every finite output length. - Two distinct states of \textbf{Neulaser} become equal after one update, giving collisions for all three variants with the initialization used by the v2 reference and optimized implementations. - An invariant subspace of \textbf{CHIME-512} permits collision search using at most \(2^{64}\) hash evaluations when shifts act separately on 64-bit words, as in both submitted implementations. - \textbf{CHAMP}'s determinant constraint gives collision searches using at most \(2^{192}\) and \(2^{384}\) hash evaluations for its 512- and 1024-bit variants, respectively. - The core permutation of \textbf{QSH} acts on \(64w\) bits and preserves a binary subspace of dimension \(16w\) through all rounds, where \(w\) is the word size. - Both version of \textbf{WChain} message expansions preserve invariant sets and admit schedules with periods one, three, and six through all prescribed rounds and final whitening. - A cyclic shift of eight binary coordinates describes \textbf{Cuishen}'s message expansion on 256 register values throughout all 64 rounds. For fixed initial chaining and counter registers, the XOR differences between round keys have periods dividing eight. The stated evaluation budgets for \textbf{CHIME-512} and \textbf{CHAMP} give success probabilities greater than \(0.39\). \keywords{Hash functions \and Cryptanalysis \and Collision attacks \and Invariant subspaces \and Message expansion}

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Hash functionsCryptanalysisCollision attacksInvariant subspacesMessage expansion
Contact author(s)
yufei2021 @ iscas ac cn
ruichen2021 @ iscas ac cn
weishanpeng2024 @ iscas ac cn
shenjunxu2024 @ iscas ac cn
liujinpeng26 @ mails ucas ac cn
zhangyixin2026 @ iscas ac cn
History
2026-09-22: approved
2026-09-22: received
See all versions
Short URL
https://ia.cr/2026/2152
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2152,
      author = {Yufei Yuan and Ruichen Wu and Shanpeng Wei and Junxu Shen and Jinpeng Liu and Yixin Zhang},
      title = {Structural Weaknesses in 7 {NGCC} Submitted Hash Functions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2152},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2152}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.