Paper 2026/2231
Truncated Differential Preimage Attacks via Differential-Linear Correlations
Abstract
We derive joint truncated differential (TD) probabilities from multiple differential-linear (DL) approximations and use them in a framework for preimage filtering. For a fixed input difference, the inverse Walsh transform recovers the probabilities of affine output cosets from DL correlations over a complete mask subspace. In our applications, these correlations are estimated using the round-based DL method. A filter accepts a selected union of affine cosets, whose probability is computed from their joint distribution without assuming independence among the DL events. The framework handles multiple targets, sharing base evaluations and confirming each accepted candidate only once. An independent sampling analysis allows candidate sets from different iterations to overlap and relates success probability to confirmation cost. Applying this framework, we obtain the first preimage attacks on KNOT-Hash below the designers' claimed preimage bounds, for $9$ to $12$ rounds. For all four JH members, we obtain preimage attacks on the reduced-round hash functions under the padding rule of the specification, covering $3$ rounds per compression-function call forJH-224/256/384 and $4$ rounds for JH-512, with speedups ranging from $2^{54}$ to $2^{158}$ over generic preimage search. For reduced-round SKINNY-Hash, we also present the first second-preimage attacks on target messages containing at least two padded blocks, covering $5$ and $6$ rounds of SKINNY-tk2-Hash and $5$, $6$, and $7$ rounds of SKINNY-tk3-Hash. As a further application of the DL-to-TD construction, we give a $6$-round TD distinguisher on Xoodoo/Xoodyak in the related-key setting, whose estimated sample complexity improves on the previous best by about $25$ bits.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Truncated differentialPreimage attacksHash functionDifferential-linear
- Contact author(s)
-
chunning zhou @ ntu edu sg
kai hu @ sdu edu cn
zhongfeng niu @ ntu edu sg
thomas peyrin @ ntu edu sg
hongyi003 @ e ntu edu sg - History
- 2026-09-28: approved
- 2026-09-27: received
- See all versions
- Short URL
- https://ia.cr/2026/2231
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2231,
author = {Chunning Zhou and Kai Hu and Zhongfeng Niu and Thomas Peyrin and Hongyi Zhang},
title = {Truncated Differential Preimage Attacks via Differential-Linear Correlations},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2231},
year = {2026},
url = {https://eprint.iacr.org/2026/2231}
}