Paper 2026/2231

Truncated Differential Preimage Attacks via Differential-Linear Correlations

Chunning Zhou, Nanyang Technological University
Kai Hu, Shandong University
Zhongfeng Niu, Nanyang Technological University
Thomas Peyrin, Nanyang Technological University
Hongyi Zhang, Nanyang Technological University
Abstract

We derive joint truncated differential (TD) probabilities from multiple differential-linear (DL) approximations and use them in a framework for preimage filtering. For a fixed input difference, the inverse Walsh transform recovers the probabilities of affine output cosets from DL correlations over a complete mask subspace. In our applications, these correlations are estimated using the round-based DL method. A filter accepts a selected union of affine cosets, whose probability is computed from their joint distribution without assuming independence among the DL events. The framework handles multiple targets, sharing base evaluations and confirming each accepted candidate only once. An independent sampling analysis allows candidate sets from different iterations to overlap and relates success probability to confirmation cost. Applying this framework, we obtain the first preimage attacks on KNOT-Hash below the designers' claimed preimage bounds, for $9$ to $12$ rounds. For all four JH members, we obtain preimage attacks on the reduced-round hash functions under the padding rule of the specification, covering $3$ rounds per compression-function call forJH-224/256/384 and $4$ rounds for JH-512, with speedups ranging from $2^{54}$ to $2^{158}$ over generic preimage search. For reduced-round SKINNY-Hash, we also present the first second-preimage attacks on target messages containing at least two padded blocks, covering $5$ and $6$ rounds of SKINNY-tk2-Hash and $5$, $6$, and $7$ rounds of SKINNY-tk3-Hash. As a further application of the DL-to-TD construction, we give a $6$-round TD distinguisher on Xoodoo/Xoodyak in the related-key setting, whose estimated sample complexity improves on the previous best by about $25$ bits.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Truncated differentialPreimage attacksHash functionDifferential-linear
Contact author(s)
chunning zhou @ ntu edu sg
kai hu @ sdu edu cn
zhongfeng niu @ ntu edu sg
thomas peyrin @ ntu edu sg
hongyi003 @ e ntu edu sg
History
2026-09-28: approved
2026-09-27: received
See all versions
Short URL
https://ia.cr/2026/2231
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2231,
      author = {Chunning Zhou and Kai Hu and Zhongfeng Niu and Thomas Peyrin and Hongyi Zhang},
      title = {Truncated Differential Preimage Attacks via Differential-Linear Correlations},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2231},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2231}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.