Paper 2026/313
Controlled Differentials in Key-Then-Hash Functions: No Absolute Weak-Key Classes and Key Recovery through MACs
Abstract
In their CRYPTO 2023 paper, Fuchs, Rotella, and Daemen reduced the universality of key-then-hash (KTH) functions built from public permutations to differential properties of the underlying permutation. Subsequent work analyzed KTH Parallel with fixed-length public functions and related variable-length universality bounds [12,13]. We develop a corresponding framework for key-recovery attacks on KTH-based MACs. We first revisit the weak-key classes identified by Handschuh and Preneel for NH, NMH*, WH, and Square Hash. For the KTH attacks considered here, these classes are solution sets of controlled differentials. These translated sets may still satisfy HP08's broad operational weak-key criterion. Our claim is different: KTH offset invariance translates every such solution set through every absolute key with unchanged probability and oracle-query cost, so the attacks do not identify intrinsically exceptional absolute keys. For these controlled attacks, this gives a strong KTH form of the UHF "regularity" sought by Handschuh and Preneel: the complete attack profile is homogeneous over absolute key space. We then show that, for every fixed-length KTH map with no probability-one nonzero differential, any two distinct key-prefix candidates can be distinguished by a generalized differential test. If its generalized derivatives are affine, one retained successful fixed-output equal-length differential leaves an affine coset and at most \(\lceil \log_2 \#S_0 \rceil\) further suitably chosen successful events determine the prefix, under the stated computational and interface assumptions. Finally, we apply the framework to NH and Xoodoo[3]. Under reusable-reference WC(S), unequal-length NH image tests simultaneously test one candidate for each word of a multiplication pair and recover both \(w\)-bit words with one generation query and at most \(2^w+1\) verification queries, approximately half the verification-query cost of the Handschuh-Preneel recovery. For Serial[Xoodoo[3]], published three-round trails yield recovery of a reusable 384-bit KTH key block in \(2^{42}\) expected differential trials, or \(2^{43}\) MAC-oracle calls.
Note: Improved the exposition and added two theorems on key distinguishability and recovery through controlled differentials.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- Message authentication codesweak-key classeskey recoverykey-then-hashdifferential cryptanalysisXoodoo
- Contact author(s)
- jonathan fuchs @ ru nl
- History
- 2026-08-18: last of 3 revisions
- 2026-02-18: received
- See all versions
- Short URL
- https://ia.cr/2026/313
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/313,
author = {Jonathan Fuchs},
title = {Controlled Differentials in Key-Then-Hash Functions: No Absolute Weak-Key Classes and Key Recovery through {MACs}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/313},
year = {2026},
url = {https://eprint.iacr.org/2026/313}
}