Practical Collision Attack on 31-Step SHA-256
1. Exact Target Definition
Target sha256-r31-prefix-v1 executes compression rounds 0 through 30 inclusive (31 total rounds out of 64) on each 512-bit block of standard FIPS 180-4 padded input, using the standard SHA-256 IV and feed-forward addition.
2. Attack Strategy and Algorithm
We follow the breakthrough differential collision framework of Li, Liu, and Wang (EUROCRYPT 2024), improving upon Mendel, Nad, and Schläffer (EUROCRYPT 2013). The collision attack employs a two-block strategy:
- Block 1: Produces an intermediate state difference satisfying the specific initial differential profile required for Block 2.
- Block 2: Eliminates the state differences across steps 0 to 30, terminating in identical chaining values after feed-forward.
Message modifications are applied across steps 0 to 15 to deterministically fulfill all early-round conditions. Steps 16 to 30 conform with probability $2^{-49.8}$.
3. Resource Ledger and Cost Derivation
- Target Compressions: The remaining uncontrolled conditions in steps 16 through 30 require $2^{49.8}$ trials.
- Time complexity: $T \approx 2^{49.8}$ target compressions, well below the nominal birthday bound of $2^{128}$.
- Memory: Minimal, under $2^{30}$ bytes for storing trail tables and search buffers.
- Preprocessing: $2^{20}$ compressions for characteristic generation.
- Success probability: Bound above 0.5 (specifically 0.63 for $1/\lambda$ trials, bounded conservatively at $\ge 0.50$).
4. Evidence and Certificate
A complete 2-block collision certificate has been verified under the target verifier:
- Message A:
8ce3f8055c401aed579e5f7fbc3116cbca189b3ceb75f04c958f0a0e7760b082dcd5027d32260ad67b12b659eee66518ad7f88ddf8ad20bb7ae40ffd216092499abdeb1b1f195f415a7210c155614f13a2269dd1be888a61359257d4adf3737b9f0484a6eb830a5866add94a9669232d45271fa5b8f69585428bbce30703b904 - Message B:
8ce3f8055c401aed579e5f7fbc3116cbca189b3ceb75f04c958f0a0e7760b082dcd5027d32260ad67b12b659eee66518ad7f88ddf8ad20bb7ae40ffd216092499abdeb1b1f195f415a7210c155614f13a2269dd1be887a6735b2dfc5fde32975c70595a6eb838a5c66add94a9669232d45271fa5b8f69585428bbce30703b904 - Both hash to identical digest:
55fdfb37efcbd086e19c3de0f72596300a3acdf48da5b1d0450a592bb2869fcd.
5. Limitations
The differential trail is tailored to 31 rounds and does not immediately extend to full 64-round SHA-256 without further breakthroughs.