





















Lingyue Qin, Tsinghua University, State Key Laboratory of Cryptology
Shiqi Hou, Tsinghua University
Xiaoyang Dong, Tsinghua University, State Key Laboratory of Cryptology
At CRYPTO 2025, Qin et al. introduced the guess-and-determine (GD) rebound attack, which integrates the guess-and-determine approach by Bouillaguet, Derbez, and Fouque and the rebound attack by Mendel et al. Taking the GD rebound as a building block, this paper introduces several classical and quantum models to convert the semi-free-start (SFS) collision attack or free-start (FS) collision attack into collision attacks on DM hashing mode with AES. As an application, the first full quantum collision attack on AES-256-DM is proposed. Despite numerous round-reduced quantum or classical attacks proposed against the three popular hash modes MMO/MP/DM with AES over the past two decades, this is the first full attack that targets one of the three fundamental security requirements: collision, (2nd) preimage resistance. Our full attack on AES-256-DM improves the best previous attack by Taiyama et al. at ASIACRYPT 2024 by 5 rounds. Besides, some improved results on AES-128-DM and AES-192-DM are also given, which have been verified partially or fully by experiments.
BibTeX
@misc{cryptoeprint:2026/1050,
author = {Liyuan Tang and Lingyue Qin and Shiqi Hou and Xiaoyang Dong},
title = {Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on {AES}-256 in {DM} Hash Mode},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1050},
year = {2026},
url = {https://eprint.iacr.org/2026/1050}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。