Paper 2026/313

Controlled Differentials in Key-Then-Hash Functions: No Absolute Weak-Key Classes and Key Recovery through MACs

Jonathan Fuchs, Radboud University Nijmegen
Abstract

In their CRYPTO 2023 paper, Fuchs, Rotella, and Daemen reduced the universality of key-then-hash (KTH) functions built from public permutations to differential properties of the underlying permutation. Subsequent work analyzed KTH Parallel with fixed-length public functions and related variable-length universality bounds [12,13]. We develop a corresponding framework for key-recovery attacks on KTH-based MACs. We first revisit the weak-key classes identified by Handschuh and Preneel for NH, NMH*, WH, and Square Hash. For the KTH attacks considered here, these classes are solution sets of controlled differentials. These translated sets may still satisfy HP08's broad operational weak-key criterion. Our claim is different: KTH offset invariance translates every such solution set through every absolute key with unchanged probability and oracle-query cost, so the attacks do not identify intrinsically exceptional absolute keys. For these controlled attacks, this gives a strong KTH form of the UHF "regularity" sought by Handschuh and Preneel: the complete attack profile is homogeneous over absolute key space. We then show that, for every fixed-length KTH map with no probability-one nonzero differential, any two distinct key-prefix candidates can be distinguished by a generalized differential test. If its generalized derivatives are affine, one retained successful fixed-output equal-length differential leaves an affine coset and at most \(\lceil \log_2 \#S_0 \rceil\) further suitably chosen successful events determine the prefix, under the stated computational and interface assumptions. Finally, we apply the framework to NH and Xoodoo[3]. Under reusable-reference WC(S), unequal-length NH image tests simultaneously test one candidate for each word of a multiplication pair and recover both \(w\)-bit words with one generation query and at most \(2^w+1\) verification queries, approximately half the verification-query cost of the Handschuh-Preneel recovery. For Serial[Xoodoo[3]], published three-round trails yield recovery of a reusable 384-bit KTH key block in \(2^{42}\) expected differential trials, or \(2^{43}\) MAC-oracle calls.

Note: Improved the exposition and added two theorems on key distinguishability and recovery through controlled differentials.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Message authentication codesweak-key classeskey recoverykey-then-hashdifferential cryptanalysisXoodoo
Contact author(s)
jonathan fuchs @ ru nl
History
2026-08-18: last of 3 revisions
2026-02-18: received
See all versions
Short URL
https://ia.cr/2026/313
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/313,
      author = {Jonathan Fuchs},
      title = {Controlled Differentials in Key-Then-Hash Functions: No Absolute Weak-Key Classes and Key Recovery through {MACs}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/313},
      year = {2026},
      url = {https://eprint.iacr.org/2026/313}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.