<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://ehash.iaik.tugraz.at/api.php?action=feedcontributions&amp;user=Crechberger&amp;feedformat=atom</id>
	<title>The ECRYPT Hash Function Website - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://ehash.iaik.tugraz.at/api.php?action=feedcontributions&amp;user=Crechberger&amp;feedformat=atom"/>
	<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/wiki/Special:Contributions/Crechberger"/>
	<updated>2024-07-08T06:58:02Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.3</generator>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Skein&amp;diff=3765</id>
		<title>Skein</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Skein&amp;diff=3765"/>
		<updated>2012-10-02T10:26:15Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Added results of four recent cryptanalysis papers&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Niels Ferguson, Stefan Lucks, Bruce Schneier, Doug Whiting, Mihir Bellare, Tadayoshi Kohno, Jon Callas, Jesse Walker&lt;br /&gt;
* Website: [http://www.schneier.com/skein.html http://www.schneier.com/skein.html]; [http://skein-hash.info/ http://skein-hash.info/]&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** Round 3: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round3/documents/Skein_FinalRnd.zip Skein_FinalRnd.zip]&lt;br /&gt;
** Round 2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Skein_Round2.zip Skein_Round2.zip]&lt;br /&gt;
** Round 1: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/SkeinUpdate.zip SkeinUpdate.zip] (old version: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Skein.zip Skein.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3F+10,&lt;br /&gt;
  author    = {Niels Ferguson and Stefan Lucks and Bruce Schneier and Doug Whiting and Mihir Bellare and Tadayoshi Kohno and Jon Callas and Jesse Walker},&lt;br /&gt;
  title     = {The Skein Hash Function Family},&lt;br /&gt;
  url        = {http://www.skein-hash.info/sites/default/files/skein1.3.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (Round 3)},&lt;br /&gt;
  year      = {2010},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3F+09,&lt;br /&gt;
  author    = {Niels Ferguson and Stefan Lucks and Bruce Schneier and Doug Whiting and Mihir Bellare and Tadayoshi Kohno and Jon Callas and Jesse Walker},&lt;br /&gt;
  title     = {The Skein Hash Function Family},&lt;br /&gt;
  url        = {http://www.skein-hash.info/sites/default/files/skein1.2.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (Round 2)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3F+08,&lt;br /&gt;
  author    = {Niels Ferguson and Stefan Lucks and Bruce Schneier and Doug Whiting and Mihir Bellare and Tadayoshi Kohno and Jon Callas and Jesse Walker},&lt;br /&gt;
  title     = {The Skein Hash Function Family},&lt;br /&gt;
  url        = {http://www.skein-hash.info/sites/default/files/skein1.1.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (Round 1)},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
Recommended security parameter: '''72''' rounds (Skein-256 and Skein-512)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the hash function according to the NIST requirements. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| collision || 256 ||  2 rounds || 2&amp;lt;sup&amp;gt;85&amp;lt;/sup&amp;gt;     || - || [http://eprint.iacr.org/2012/141.pdf Khovratovich]&lt;br /&gt;
|-&lt;br /&gt;
| collision || 256 || 12 rounds || 2&amp;lt;sup&amp;gt;126.5&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2012/141.pdf Khovratovich]&lt;br /&gt;
|-&lt;br /&gt;
| collision || 512 || 5 rounds  || 2&amp;lt;sup&amp;gt;192&amp;lt;/sup&amp;gt;    || - || [http://eprint.iacr.org/2012/141.pdf Khovratovich]&lt;br /&gt;
|-&lt;br /&gt;
| collision || 512 || 14 rounds || 2&amp;lt;sup&amp;gt;254.5&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2012/141.pdf Khovratovich]&lt;br /&gt;
|-                    &lt;br /&gt;
| preimage || 512 || 22 rounds || 2&amp;lt;sup&amp;gt;511.0&amp;lt;/sup&amp;gt;  || 2&amp;lt;sup&amp;gt;6&amp;lt;/sup&amp;gt; || [http://eprint.iacr.org/2011/286.pdf Khovratovich,Rechberger,Savelieva]&lt;br /&gt;
|-                    &lt;br /&gt;
| preimage || 512 || 72 rounds || 2&amp;lt;sup&amp;gt;511.76&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2011/286.pdf Khovratovich,Rechberger,Savelieva]&lt;br /&gt;
|-                    &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks). &lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-&lt;br /&gt;
| preimage || compression function || 512 || 22 rounds || 2&amp;lt;sup&amp;gt;508&amp;lt;/sup&amp;gt;  ||  2&amp;lt;sup&amp;gt;6&amp;lt;/sup&amp;gt;  || [http://eprint.iacr.org/2011/286.pdf Khovratovich,Rechberger,Savelieva]&lt;br /&gt;
|-&lt;br /&gt;
| preimage || compression function || 512 || 37 rounds || 2&amp;lt;sup&amp;gt;511.2&amp;lt;/sup&amp;gt;  || 2&amp;lt;sup&amp;gt;64&amp;lt;/sup&amp;gt; || [http://eprint.iacr.org/2011/286.pdf Khovratovich,Rechberger,Savelieva]&lt;br /&gt;
|-&lt;br /&gt;
| distinguisher || compression function || 512 || 32 rounds || 2&amp;lt;sup&amp;gt;104.5&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2012/238.pdf Yu,Chen,Wang]&lt;br /&gt;
|-&lt;br /&gt;
| distinguisher || compression function || 512 || 36 rounds || 2&amp;lt;sup&amp;gt;454&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2012/238.pdf Yu,Chen,Wang]&lt;br /&gt;
|-&lt;br /&gt;
| key recovery || block cipher || 512 || 32 rounds || 2&amp;lt;sup&amp;gt;181&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2012/238.pdf Yu,Chen,Wang]&lt;br /&gt;
|-&lt;br /&gt;
| key recovery || block cipher || 512 || 34 rounds || 2&amp;lt;sup&amp;gt;424&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2012/238.pdf Yu,Chen,Wang]&lt;br /&gt;
|-&lt;br /&gt;
| near-collision || compression function || 256 || 32 rounds || 2&amp;lt;sup&amp;gt;105&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2011/148.pdf Yu,Chen,Jia,Wang]&lt;br /&gt;
|-&lt;br /&gt;
| distinguisher || compression function || all || 57 rounds  (Round 2) || 2&amp;lt;sup&amp;gt;503&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2010/538.pdf Khovratovich,Nikolić,Rechberger]&lt;br /&gt;
|-&lt;br /&gt;
| distinguisher || compression function || 256 || 53 rounds (Round 2) || 2&amp;lt;sup&amp;gt;251&amp;lt;/sup&amp;gt;, Skein-256  || - || [http://eprint.iacr.org/2010/538.pdf Khovratovich,Nikolić,Rechberger]&lt;br /&gt;
|-&lt;br /&gt;
| near-collision || compression function || all || 24 rounds (No. 20-43) || 2&amp;lt;sup&amp;gt;230&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2010/355.pdf Su,Wu,Wu,Dong]&lt;br /&gt;
|-&lt;br /&gt;
| near-collision || compression function || 256 || 24 rounds (No. 12-35), Skein-256 || 2&amp;lt;sup&amp;gt;60&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2010/355.pdf Su,Wu,Wu,Dong]&lt;br /&gt;
|-&lt;br /&gt;
| near-collision || compression function || all || 24 rounds, Skein-1024 || 2&amp;lt;sup&amp;gt;395&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2010/355.pdf Su,Wu,Wu,Dong]&lt;br /&gt;
|-&lt;br /&gt;
|  observations || hash || all || ||  ||  || [http://people.item.ntnu.no/~danilog/Hash/Non-random-behaviour-narrow-pipe-designs-03.pdf Gligoroski]&lt;br /&gt;
|-&lt;br /&gt;
|  observations || block cipher || all || - || - || - || [http://eprint.iacr.org/2010/282.pdf McKay,Vora]&lt;br /&gt;
|-&lt;br /&gt;
|  observations || compression function || all || - || - || - || [http://eprint.iacr.org/2010/262.pdf Kaminsky]&lt;br /&gt;
|-&lt;br /&gt;
|  key recovery || block cipher || 256 || 39 rounds || 2&amp;lt;sup&amp;gt;254.1&amp;lt;/sup&amp;gt; || - || [http://cryptolux.org/mediawiki/uploads/5/5b/Rotational_Cryptanalysis_of_Skein.pdf Khovratovich,Nikolic]&lt;br /&gt;
|-&lt;br /&gt;
|  key recovery || block cipher || 512 || 42 rounds|| 2&amp;lt;sup&amp;gt;507&amp;lt;/sup&amp;gt; || - || [http://cryptolux.org/mediawiki/uploads/5/5b/Rotational_Cryptanalysis_of_Skein.pdf Khovratovich,Nikolic]&lt;br /&gt;
|-    &lt;br /&gt;
|  key recovery || block cipher || 512 || 32 rounds (Round 1) || 2&amp;lt;sup&amp;gt;226&amp;lt;/sup&amp;gt; (2&amp;lt;sup&amp;gt;222&amp;lt;/sup&amp;gt;) || 2&amp;lt;sup&amp;gt;12&amp;lt;/sup&amp;gt; || [http://eprint.iacr.org/2009/526.pdf Chen,Jia]&lt;br /&gt;
|-  &lt;br /&gt;
|  key recovery || block cipher || 512 || 33 rounds (Round 1) || 2&amp;lt;sup&amp;gt;352.17&amp;lt;/sup&amp;gt; (2&amp;lt;sup&amp;gt;355.5&amp;lt;/sup&amp;gt;) || - || [http://eprint.iacr.org/2009/526.pdf Chen,Jia]&lt;br /&gt;
|-&lt;br /&gt;
|  near collision || compression function || 512 || 17 rounds (Round 1) || 2&amp;lt;sup&amp;gt;24&amp;lt;/sup&amp;gt; || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|-     &lt;br /&gt;
|  distinguisher || block cipher || 512 || 35 rounds (Round 1) || 2&amp;lt;sup&amp;gt;478&amp;lt;/sup&amp;gt; || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|- &lt;br /&gt;
|  impossible differential || block cipher || 512 || 21 rounds (Round 1) || - || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|-        &lt;br /&gt;
|  key recovery || block cipher || 512 || 32 rounds (Round 1) || 2&amp;lt;sup&amp;gt;312&amp;lt;/sup&amp;gt; || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|-    &lt;br /&gt;
|}        &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinK12,&lt;br /&gt;
    author = {Dmitry Khovratovich},&lt;br /&gt;
    title = {Bicliques for permutations: collision and preimage attacks in stronger settings},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2012/141},&lt;br /&gt;
    year = {2012},&lt;br /&gt;
    url = {http://eprint.iacr.org/2012/141.pdf},&lt;br /&gt;
    abstract = { We extend and improve biclique attacks, which were recently introduced for the cryptanalysis of block ciphers and hash functions. While previous attacks required a primitive to have a key or a message schedule, we show how to mount attacks on the primitives with these parameters fixed, i.e. on permutations. We introduce the concept of sliced bicliques, which is a translation of regular bicliques to the framework with permutations.&lt;br /&gt;
&lt;br /&gt;
The new framework allows to convert preimage attacks into collision attacks and derive the first collision attacks on the reduced SHA-3 finalist Skein in the hash function setting up to 11 rounds. We also demonstrate new preimage attacks on the reduced Skein and the output transformation of the reduced Gr{\o}stl. Finally, the sophisticated technique of message compensation gets a simple explanation with bicliques. }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{skeinKRS12,&lt;br /&gt;
  author = {Dmitry Khovratovich and Christian Rechberger and Alexandra Savelieva},&lt;br /&gt;
  title = {Bicliques for Preimages: Attacks on Skein-512 and the SHA-2 family},&lt;br /&gt;
  booktitle = {Fast Software Encryption (FSE)},&lt;br /&gt;
  year      = {2012},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  url = {http://eprint.iacr.org/2011/286.pdf},&lt;br /&gt;
  abstract = {We present the new concept of biclique as a tool for preimage attacks, which&lt;br /&gt;
employs many powerful techniques from differential cryptanalysis of block ciphers and hash&lt;br /&gt;
functions.&lt;br /&gt;
The new tool has proved to be widely applicable by inspiring many authors to publish new re-&lt;br /&gt;
sults of the full versions of AES, KASUMI, IDEA, and Square. In this paper, we demonstrate&lt;br /&gt;
how our concept results in the first cryptanalysis of the Skein hash function, and describe an&lt;br /&gt;
attack on the SHA-2 hash function with more rounds than before.}&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinY+12,&lt;br /&gt;
    author = {Hongbo Yu and Jiazhe Chen and Xiaoyun Wang},&lt;br /&gt;
    title = {The Boomerang Attacks on the Round-Reduced Skein-512},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2012/238},&lt;br /&gt;
    year = {2012},&lt;br /&gt;
    url = {http://eprint.iacr.org/2012/238.pdf},&lt;br /&gt;
    abstract = {The hash function Skein is one of the five finalists of the NIST SHA-3 competition;it is based on the block cipher Threefish which only uses three primitive operations: modular addition, rotation and bitwise XOR (ARX). This paper studies the boomerang attacks on Skein-512. Boomerang distinguishers on the compression function reduced to 32 and 36 rounds are proposed, with complexities 2^{104.5} and 2^{454} respectively. Examples of the distinguishers on 28-round and 31-round are also given. In addition, the boomerang distinguishers are applicable to the key-recovery attacks on reduced Threefish-512. The complexities for key-recovery attacks reduced to 32-/33-/34-round are about 2^{181}, 2^{305} and 2^{424}. Because Laurent et al. [14] pointed out that the previous boomerang distinguishers for Threefish-512 are in fact not compatible, our attacks are the first valid boomerang attacks for the final round Skein-512.  }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinY+12,&lt;br /&gt;
    author = {Hongbo Yu and Jiazhe Chen and Ketingjia and Xiaoyun Wang},&lt;br /&gt;
    title = {Near-Collision Attack on the Step-Reduced Compression Function of Skein-256},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2011/148},&lt;br /&gt;
    year = {2011},&lt;br /&gt;
    url = {http://eprint.iacr.org/2011/148.pdf},&lt;br /&gt;
    abstract = {The Hash function Skein is one of the 5 finalists of NIST SHA-3 competition. It is designed based on the threefish block cipher and it only uses three primitive operations: modular addition, rotation and bitwise XOR (ARX). In this paper, we combine two short differential paths to a long differential path using the modular differential technique. And we present the semi-free start near-collision attack up to the 32-step Skein-256 with the Hamming difference 51. The complexity of our attack is about $2^{105}$. }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{skeinKNR10,&lt;br /&gt;
  author = {Dmitry Khovratovich and Ivica Nikolić and Christian Rechberger},&lt;br /&gt;
  title = {Rotational Rebound Attacks on Reduced Skein},&lt;br /&gt;
  booktitle = {ASIACRYPT},&lt;br /&gt;
  year      = {2010},&lt;br /&gt;
  pages     = {1-19},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  volume    = {6477},&lt;br /&gt;
  url = {http://eprint.iacr.org/2010/538.pdf},&lt;br /&gt;
  abstract = {In this paper we combine the recent rotational cryptanalysis with the rebound attack, which results in the best cryptanalysis of Skein, a candidate for the SHA-3 competition. The rebound attack approach was so far only applied to AES-like constructions. For the first time, we show that this approach can also be applied to very different constructions. In more detail, we develop a number of techniques that extend the reach of both the inbound and the outbound phase, leading to rotational collisions for about 53/57 out of the 72 rounds of the Skein-256/512 compression function and the Threefish cipher. At this point, the results do not threaten the security of the full-round Skein hash function.&lt;br /&gt;
&lt;br /&gt;
The new techniques include an analytical search for optimal input values in the rotational cryptanalysis, which allows to extend the outbound phase of the attack with a precomputation phase, an approach never used in any rebound-style attack before. Further we show how to combine multiple inside-out computations and neutral bits in the inbound phase of the rebound attack, and give well-defined rotational distinguishers as certificates of weaknesses for the compression functions and block ciphers.}&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{skeinSuWWD10,&lt;br /&gt;
  author = {Bozhan Su and Wenling Wu and Shuang Wu and Le Dong},&lt;br /&gt;
  title = {Near-Collisions on the Reduced-Round Compression Functions of Skein and BLAKE},&lt;br /&gt;
  booktitle = {CANS},&lt;br /&gt;
  year      = {2010},&lt;br /&gt;
  pages     = {124-139},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  volume    = {6467},&lt;br /&gt;
  url = {http://eprint.iacr.org/2010/355.pdf},&lt;br /&gt;
  abstract = {The SHA-3 competition organized by NIST aims to find a new hash standard as a replacement of SHA-2. Till now, 14 submissions have been selected as the second round candidates, including Skein and BLAKE, both of which have components based on modular addition, rotation and bitwise XOR (ARX). In this paper, we propose improved near-collision attacks on the reduced-round compression functions of Skein and a variant of BLAKE. The attacks are based on linear differentials of the modular additions. The computational complexity of near-collision attacks on a 4-round compression function of BLAKE-32, 4-round and 5-round compression functions of BLAKE-64 are 2^{21}, 2^{16} and 2^{216} respectively, and the attacks on a 24-round compression functions of Skein-256, Skein-512 and Skein-1024 have a complexity of 2^{60}, 2^{230} and 2^{395} respectively.}&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinGli10,&lt;br /&gt;
  author    = {Danilo Gligoroski},&lt;br /&gt;
  title     = {Narrow-pipe SHA-3 candidates differ significantly from ideal random functions defined over big domains},&lt;br /&gt;
  url        = {http://people.item.ntnu.no/~danilog/Hash/Non-random-behaviour-narrow-pipe-designs-03.pdf},&lt;br /&gt;
  howpublished = {NIST mailing list},&lt;br /&gt;
  year      = {2010},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinMV10,&lt;br /&gt;
    author = {Kerry A. McKay and Poorvi L. Vora},&lt;br /&gt;
    title = {Pseudo-Linear Approximations for ARX Ciphers: With Application to Threefish},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2010/282},&lt;br /&gt;
    year = {2010},&lt;br /&gt;
    url = {http://eprint.iacr.org/2010/282.pdf},&lt;br /&gt;
    abstract = {The operations addition modulo 2^n and exclusive-or have recently been combined to obtain an efficient mechanism for nonlinearity in block cipher design. In this paper, we show that ciphers using this approach may be approximated by pseudo-linear expressions relating groups of contiguous bits of the round key, round input, and round output. The bias of an approximation can be large enough for known plaintext attacks. We demonstrate an application of this concept to a reduced-round version of the Threefish block cipher, a component of the Skein entry in the secure hash function competition.}&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinKam10,&lt;br /&gt;
    author = {Alan Kaminsky},&lt;br /&gt;
    title = {Cube Test Analysis of the Statistical Behavior of CubeHash and Skein},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2010/262},&lt;br /&gt;
    year = {2010},&lt;br /&gt;
    url = {http://eprint.iacr.org/2010/262.pdf},&lt;br /&gt;
    abstract = {This work analyzes the statistical properties of the SHA-3 candidate cryptographic hash algorithms CubeHash and Skein to try to find nonrandom behavior. Cube tests were used to probe each algorithm's internal polynomial structure for a large number of choices of the polynomial input variables. The cube test data were calculated on a 40-core hybrid SMP cluster parallel computer. The cube test data were subjected to three statistical tests: balance, independence, and off-by-one. Although isolated statistical test failures were observed, the balance and off-by-one tests did not find nonrandom behavior overall in either CubeHash or Skein. However, the independence test did find nonrandom behavior overall in both CubeHash and Skein. }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{cryptoeprint:2009:526,&lt;br /&gt;
    author = {Dmitry Khovratovich and Ivica Nikolic},&lt;br /&gt;
    title = {Rotational Cryptanalysis of ARX},&lt;br /&gt;
  pages     = {333-346},&lt;br /&gt;
  booktitle = {FSE},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  volume    = {6147},&lt;br /&gt;
    url = {http://cryptolux.org/mediawiki/uploads/5/5b/Rotational_Cryptanalysis_of_Skein.pdf},&lt;br /&gt;
    abstract = {In this paper we analyze the security of systems based on&lt;br /&gt;
modular additions, rotations, and XORs (ARX systems). We provide&lt;br /&gt;
both theoretical support for their security and practical cryptanalysis of&lt;br /&gt;
real ARX primitives. We use a technique called rotational cryptanalysis,&lt;br /&gt;
that is universal for the ARX systems and is quite efficient. We illustrate&lt;br /&gt;
the method with the best known attack on reduced versions of the block&lt;br /&gt;
cipher Threeﬁsh (the core of Skein). Additionally, we prove that ARX&lt;br /&gt;
with constants are functionally complete, i.e. any function can be realized&lt;br /&gt;
with these operations.&lt;br /&gt;
},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cryptoeprint:2009:526,&lt;br /&gt;
    author = {Jiazhe Chen and Keting Jia},&lt;br /&gt;
    title = {Improved Related-key Boomerang Attacks on Round-Reduced Threefish-512},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/526},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/526.pdf},&lt;br /&gt;
    abstract = {Hash function Skein is one of the 14 NIST SHA-3 second round candidates. Threefish is a tweakable block cipher as the core of Skein, defined with a 256-, 512-, and 1024-bit block size. The 512-bit block size is the primary proposal of the authors. In this paper we construct two related-key boomerang distinguishers on round-reduced Threefish-512 using the method of \emph{modular differential}. With a distinguisher on 32 rounds of Threefish-512, we improve the key recovery attack on 32 rounds of Threefish-512 proposed by Aumasson et al. Their attack requires $2^{312}$ encryptions and $2^{71}$ bytes of memory. However, our attack has a time complexity of $2^{226}$ encryptions with memory of $2^{12}$ bytes. Furthermore, we give a key recovery attack on Threefish-512 reduced to 33 rounds using a 33-round related-key boomerang distinguisher, with $2^{352.17}$ encryptions and negligible memory. Skein had been updated after it entered the second round and the results above are based on the original version. However, as the only differences between the original and the new version are the rotation constants, both of the methods can be applied to the new version with modified differential trails. For the new rotation constants, our attack on 32-round Threefish-512 has a time complexity $2^{222}$ and $2^{12}$ bytes' memory. Our attack on 33-round Threefish-512 has a time complexity $2^{355.5}$ and negligible memory.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{skeinA+09,&lt;br /&gt;
    author = {Jean-Philippe Aumasson and Cagdas Calik and Willi Meier and Onur Ozen and Raphael C.-W. Phan and Kerem Varici},&lt;br /&gt;
    title = {Improved Cryptanalysis of Skein},&lt;br /&gt;
  booktitle = {ASIACRYPT},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  pages     = {542-559},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  volume    = {5912},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/438.pdf},&lt;br /&gt;
    abstract={The hash function Skein is the submission of Ferguson et al. to the NIST Hash Competition, and is arguably a serious candidate for selection as SHA-3. This paper presents the first third-party analysis of Skein, with an extensive study of its main component: the block cipher Threefish. We notably investigate near collisions, distinguishers, impossible differentials, key recovery using related-key differential and boomerang attacks. In particular, we present near collisions on up to 17 rounds, an impossible differential on 21 rounds, a related-key boomerang distinguisher on 34 rounds, a known-related-key boomerang distinguisher on 35 rounds, and key recovery attacks on up to 32 rounds, out of 72 in total for Threefish-512. None of our attacks directly extends to the full Skein hash. However, the pseudorandomness of Threefish is required to validate the security proofs on Skein, and our results conclude that at least 36 rounds of Threefish seem required for optimal security guarantees.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{SkeinAum09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Willi Meier and Raphael Phan},&lt;br /&gt;
  title     = {Improved analyis of Threefish},&lt;br /&gt;
  url = {http://131002.net/data/talks/threefish_rump.pdf},&lt;br /&gt;
  howpublished = {FSE 2009 rump session, slides available online},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=SHA-3_related_events&amp;diff=3719</id>
		<title>SHA-3 related events</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=SHA-3_related_events&amp;diff=3719"/>
		<updated>2011-11-03T19:41:09Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added ISI Kolkata workshop&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On this page, we list events like conferences, workshops, panel discussions, etc. that are especially interesting in the context of the SHA-3 competition.&lt;br /&gt;
&lt;br /&gt;
Upcoming:&lt;br /&gt;
&lt;br /&gt;
[http://www.isical.ac.in/~coec/workshop/hash2011.html Hash Workshop on SHA3 Finalists] December 9-10, 2011, Kolkata.&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round3/March2012/index.html Third SHA-3 Candidate Conference] March 22-23, 2012, Washington D.C.&lt;br /&gt;
&lt;br /&gt;
Archive:&lt;br /&gt;
&lt;br /&gt;
[http://www.ecrypt.eu.org/stvl/hfw/ ECRYPT Conference on Hashfunctions 2005]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/first_workshop.html NIST Cryptographic Hash Workshop 2005]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/second_workshop.html NIST Cryptographic Hash Workshop 2006]&lt;br /&gt;
&lt;br /&gt;
[http://events.iaik.tugraz.at/HashWorkshop07/ ECRYPT Hash Workshop 2007]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/Feb2009/index.html First SHA-3 Candidate Conference]&lt;br /&gt;
&lt;br /&gt;
[https://www.cosic.esat.kuleuven.be/ecrypt/courses/tenerife09/program.shtml Hash³: Proofs, Analysis, and Implementation]&lt;br /&gt;
&lt;br /&gt;
[http://www.iwsec.org/2009/program.html#pd Cryptographic hash functions: SHA-3 and beyond]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/Aug2010/index.html Second SHA-3 Candidate Conference]&lt;br /&gt;
&lt;br /&gt;
[http://www.ecrypt.eu.org/hash2011/ ECRYPT2 Hash Workshop 2011] May 19-20, 2011, Tallinn, Estonia&lt;br /&gt;
&lt;br /&gt;
[http://cryptography.gmu.edu/quovadis/ Quo Vadis Cryptology 2011] May 23-24, 2011, Warsaw, Poland&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your event is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=SHA-3_related_events&amp;diff=3712</id>
		<title>SHA-3 related events</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=SHA-3_related_events&amp;diff=3712"/>
		<updated>2011-05-08T05:26:42Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added Quo Vadis Cryptology&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On this page, we list events like conferences, workshops, panel discussions, etc. that are especially interesting in the context of the SHA-3 competition.&lt;br /&gt;
&lt;br /&gt;
Upcoming:&lt;br /&gt;
&lt;br /&gt;
[http://www.ecrypt.eu.org/hash2011/ ECRYPT2 Hash Workshop 2011] May 19-20, 2011, Tallinn, Estonia&lt;br /&gt;
&lt;br /&gt;
[http://cryptography.gmu.edu/quovadis/ Quo Vadis Cryptology 2011] May 23-24, 2011, Warsaw, Poland&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round3/March2012/index.html Third SHA-3 Candidate Conference] March 22-23, 2012, Washington D.C.&lt;br /&gt;
&lt;br /&gt;
Archive:&lt;br /&gt;
&lt;br /&gt;
[http://www.ecrypt.eu.org/stvl/hfw/ ECRYPT Conference on Hashfunctions 2005]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/first_workshop.html NIST Cryptographic Hash Workshop 2005]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/second_workshop.html NIST Cryptographic Hash Workshop 2006]&lt;br /&gt;
&lt;br /&gt;
[http://events.iaik.tugraz.at/HashWorkshop07/ ECRYPT Hash Workshop 2007]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/Feb2009/index.html First SHA-3 Candidate Conference]&lt;br /&gt;
&lt;br /&gt;
[https://www.cosic.esat.kuleuven.be/ecrypt/courses/tenerife09/program.shtml Hash³: Proofs, Analysis, and Implementation]&lt;br /&gt;
&lt;br /&gt;
[http://www.iwsec.org/2009/program.html#pd Cryptographic hash functions: SHA-3 and beyond]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/Aug2010/index.html Second SHA-3 Candidate Conference]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your event is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3710</id>
		<title>The SHA-3 Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3710"/>
		<updated>2011-04-27T18:21:04Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added events page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The SHA-3 Zoo (work in progress) is a collection of cryptographic hash functions (in alphabetical order) submitted to the [http://www.nist.gov/hash-competition SHA-3 contest] (see also [http://en.wikipedia.org/wiki/SHA-3 here]). It aims to provide an overview of design and cryptanalysis of all submissions. A list of all [[SHA-3 submitters]] is also available. For a software performance related overview, see [http://bench.cr.yp.to/ebash.html eBASH]. At a separate page, we also collect [[SHA-3_Hardware_Implementations | hardware implementation results]] of the candidates. Another categorization of the SHA-3 submissions can be found [http://eprint.iacr.org/2008/511.pdf here].&lt;br /&gt;
&lt;br /&gt;
The idea of the SHA-3 Zoo is to give a good overview of cryptanalytic results. We try to avoid additional judgement whether a submission is broken. The answer to this question is left to NIST. However, we categorize the cryptanalytic results by their impact from very theoretic to practical attacks. A detailed description is given in [[Cryptanalysis Categories]].&lt;br /&gt;
&lt;br /&gt;
At this time, 56 out of 64 submissions to the SHA-3 competition are publicly known and available. 51 submissions have advanced to [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/index.html round 1], 14 submissions have made it into [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/index.html round 2] and 5 candidates have been selected for the [http://csrc.nist.gov/groups/ST/hash/sha-3/Round3/index.html final].&lt;br /&gt;
&lt;br /&gt;
The following table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are collected at the individual hash function pages. A description of the main table is given [[Cryptanalysis_Categories#Main_Cryptanalysis_Table | here]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The 5 finalists of the SHA-3 competition are:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;150&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;140&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[BLAKE]]        || Jean-Philippe Aumasson || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Groestl|Grøstl]] || Lars R. Knudsen || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[JH]]           || Hongjun Wu || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Keccak]]       || The Keccak Team || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Skein]]        || Bruce Schneier || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/index.php?title=Special:Recentchangeslinked&amp;amp;target=The_SHA-3_Zoo&amp;amp;days=7&amp;amp;limit=50&amp;amp;hideminor=1 Recent updates of the SHA-3 Zoo]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font color=red&amp;gt;new:&amp;lt;/font&amp;gt;[[SHA-3 related events]]&lt;br /&gt;
&lt;br /&gt;
Your analysis is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font color=red&amp;gt;Call for contribution:&amp;lt;/font&amp;gt;&lt;br /&gt;
A subgroup of STVL in ECRYPT2 started working on an Ecrypt report on the status of the SHA-3 finalists. The report will contain a survey of the results published on the finalists. If you recently obtained new results, which are not public yet and you want to see them included in the report, please contact vincent.rijmen@iaik.tugraz.at .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following SHA-3 candidates advanced to round 2 but did not get into the final:&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/uploads/c/ce/20090922-2230_SHA-3_round2_tweaks.pdf Round 2 tweaks for all candidates]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;150&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;140&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Blue Midnight Wish]] || Svein Johan Knapskog || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[CubeHash]]     || Daniel J. Bernstein || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[ECHO]]         || Henri Gilbert || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Fugue]]        || Charanjit S. Jutla || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Hamsi]]        || &amp;lt;nowiki&amp;gt;Özgül Kü&amp;amp;#231;ük&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Luffa]]        || Dai Watanabe || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Shabal]]       || &amp;lt;nowiki&amp;gt;Jean-Fran&amp;amp;#231;ois Misarsky&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAvite-3]]    || Orr Dunkelman || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SIMD]]         || &amp;lt;nowiki&amp;gt;Ga&amp;amp;#235;tan Leurent&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following submitted hash functions have not advanced to round 2:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot; | Status !! width=&amp;quot;150&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;140&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Abacus]]      || Neil Sholer || in round 1 || style=&amp;quot;background:orange&amp;quot; | 2nd-preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[ARIRANG]]      || Jongin Lim || in round 1 || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[AURORA]]       || Masahiro Fujita  || in round 1|| style=&amp;quot;background:orange&amp;quot;| 2nd preimage  ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Blender]]      || Colin Bradbury || in round 1|| style=&amp;quot;background:orange&amp;quot; | collision, preimage  || near-collision&lt;br /&gt;
|-  &lt;br /&gt;
| [[Boole]]       || Greg Rose || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                           &lt;br /&gt;
| [[Cheetah]]      || Dmitry Khovratovich || in round 1||  || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CHI]]          || Phillip Hawkes || in round 1|| ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[CRUNCH]]       || Jacques Patarin || in round 1||  || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[DCH]]         || David A. Wilson || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA]]  || Xu Zijie || in round 1|| style=&amp;quot;background:red&amp;quot;|collision || length-extension &lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA2]] || Xu Zijie || in round 1|| style=&amp;quot;background:orange&amp;quot;|collision  || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[ECOH]]         || Daniel R. L. Brown || in round 1|| style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R (SHA-3 submission)|Edon-R]] || Danilo Gligoroski || in round 1|| style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[EnRUPT]]       || Sean O'Neil || in round 1|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ESSENCE]]      || Jason Worth Martin || in round 1|| style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB (SHA-3 submission) | FSB]] || Matthieu Finiasz || in round 1|| ||&lt;br /&gt;
|-&lt;br /&gt;
| [[HASH 2X]]     || Jason Lee || not in round 1 || style=&amp;quot;background:red&amp;quot; | 2nd-preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Khichidi-1]]  || M. Vidyasagar || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LANE]]         || Sebastiaan Indesteege || in round 1|| ||&lt;br /&gt;
|-                         &lt;br /&gt;
| [[Lesamnta]]     || Hirotaka Yoshida || in round 1|| ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LUX]]          || &amp;lt;nowiki&amp;gt;Ivica Nikoli&amp;amp;#263;&amp;lt;/nowiki&amp;gt; || in round 1|| style=&amp;quot;background:orange&amp;quot; | collision, 2nd preimage || DRBG,HMAC&lt;br /&gt;
|-             &lt;br /&gt;
| [[Maraca]]      || Robert J. Jenkins || not in round 1 || style=&amp;quot;background:red&amp;quot; | preimage ||&lt;br /&gt;
|-  &lt;br /&gt;
| [[MCSSHA-3]]     || Mikhail Maslennikov || in round 1|| style=&amp;quot;background:orange&amp;quot; | 2nd preimage ||&lt;br /&gt;
|-                                                                                             &lt;br /&gt;
| [[MD6]]          || Ronald L. Rivest || in round 1|| ||&lt;br /&gt;
|-     &lt;br /&gt;
| [[MeshHash]]    || Björn Fay || in round 1 || style=&amp;quot;background:orange&amp;quot; | 2nd preimage ||&lt;br /&gt;
|-                                                                                                         &lt;br /&gt;
| [[NaSHA]]        || Smile Markovski || in round 1|| style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[NKS2D]]       || Geoffrey Park || not in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Ponic]]       || Peter Schmidt-Nielsen || not in round 1 || style=&amp;quot;background:yellow&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[SANDstorm]]    || Rich Schroeppel || in round 1|| ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Sarmal]]       || &amp;lt;nowiki&amp;gt;Kerem Var&amp;amp;#305;c&amp;amp;#305;&amp;lt;/nowiki&amp;gt; || in round 1||  style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Sgàil]]        || Peter Maxwell|| in round 1|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAMATA]]      || Orhun Kara || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Spectral Hash]] || &amp;lt;nowiki&amp;gt;&amp;amp;#199;etin Kaya Ko&amp;amp;#231;&amp;lt;/nowiki&amp;gt; || in round 1|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[StreamHash]]   || Michal Trojnara || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFTX]]      || Daniele Micciancio || in round 1|| ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Tangle]]      || Rafael Alvarez || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[TIB3]]         || Daniel Penazzi || in round 1|| style=&amp;quot;background:yellow&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Twister]]      || Michael Gorski || in round 1|| style=&amp;quot;background:orange&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Vortex (SHA-3 submission)|Vortex]] || Michael Kounavis || in round 1|| style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[WaMM]]        || John Washburn || in round 1 || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Waterfall]]   || Bob Hattersley || in round 1 || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[ZK-Crypt]]       || Carmi Gressel || not in round 1 || ||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=SHA-3_related_events&amp;diff=3709</id>
		<title>SHA-3 related events</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=SHA-3_related_events&amp;diff=3709"/>
		<updated>2011-04-27T18:20:31Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Start of events page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On this page, we list events like conferences, workshops, panel discussions, etc. that are especially interesting in the context of the SHA-3 competition.&lt;br /&gt;
&lt;br /&gt;
Upcoming:&lt;br /&gt;
&lt;br /&gt;
[http://www.ecrypt.eu.org/hash2011/ ECRYPT2 Hash Workshop 2011] May 19-20, 2011, Tallinn, Estonia&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round3/March2012/index.html Third SHA-3 Candidate Conference] March 22-23, 2012, Washington D.C.&lt;br /&gt;
&lt;br /&gt;
Archive:&lt;br /&gt;
&lt;br /&gt;
[http://www.ecrypt.eu.org/stvl/hfw/ ECRYPT Conference on Hashfunctions 2005]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/first_workshop.html NIST Cryptographic Hash Workshop 2005]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/second_workshop.html NIST Cryptographic Hash Workshop 2006]&lt;br /&gt;
&lt;br /&gt;
[http://events.iaik.tugraz.at/HashWorkshop07/ ECRYPT Hash Workshop 2007]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/Feb2009/index.html First SHA-3 Candidate Conference]&lt;br /&gt;
&lt;br /&gt;
[https://www.cosic.esat.kuleuven.be/ecrypt/courses/tenerife09/program.shtml Hash³: Proofs, Analysis, and Implementation]&lt;br /&gt;
&lt;br /&gt;
[http://www.iwsec.org/2009/program.html#pd Cryptographic hash functions: SHA-3 and beyond]&lt;br /&gt;
&lt;br /&gt;
[http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/Aug2010/index.html Second SHA-3 Candidate Conference]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your event is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=User:Crechberger&amp;diff=3708</id>
		<title>User:Crechberger</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=User:Crechberger&amp;diff=3708"/>
		<updated>2011-04-27T18:20:22Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[http://groestl.info/rechberger Christian Rechberger]&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Shabal&amp;diff=3550</id>
		<title>Shabal</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Shabal&amp;diff=3550"/>
		<updated>2010-07-27T00:58:34Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added Novotney distinguisher&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Emmanuel Bresson, Anne Canteaut, Benoît Chevallier-Mames, Christophe Clavier, Thomas Fuhr, Aline Gouget, Thomas Icart, Jean-François Misarsky, Marìa Naya-Plasencia, Pascal Paillier, Thomas Pornin, Jean-René Reinhard, Céline Thuillet, Marion Videau&lt;br /&gt;
* Website: http://www.shabal.com/&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** round 1/2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Shabal_Round2.zip Shabal_Round2.zip] (old version: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Shabal.zip Shabal.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3CanteautCGPP08,&lt;br /&gt;
  author    = {Emmanuel Bresson and Anne Canteaut and Benoît Chevallier-Mames and Christophe Clavier and Thomas Fuhr and Aline Gouget and Thomas Icart and Jean-François Misarsky and Marìa Naya-Plasencia and Pascal Paillier and Thomas Pornin and Jean-René Reinhard and Céline Thuillet and Marion Videau},&lt;br /&gt;
  title     = {Shabal, a Submission to NIST’s Cryptographic Hash Algorithm Competition},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/6/6c/Shabal.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cryptoeprint:2009:199,&lt;br /&gt;
    author = {Emmanuel Bresson and Anne Canteaut and Benoît Chevallier-Mames and Christophe Clavier and Thomas Fuhr and Aline Gouget and Thomas Icart and Jean-François Misarsky and Marìa Naya-Plasencia and Pascal Paillier and Thomas Pornin and Jean-René Reinhard and Céline Thuillet and Marion Videau},&lt;br /&gt;
    title = {Indifferentiability with Distinguishers: Why Shabal Does Not Require Ideal Ciphers},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/199},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/199.pdf},&lt;br /&gt;
    abstract = {Shabal is based on a new provably secure mode of operation. Some related-key distinguishers for the underlying keyed permutation have been exhibited recently by Aumasson et al. and Knudsen et al., but with no visible impact on the security of Shabal. This paper then aims at extensively studying such distinguishers for the keyed permutation used in Shabal, and at clarifying the impact that they exert on the security of the full hash function. Most interestingly, a new security proof for Shabal's mode of operation is provided where the keyed permutation is not assumed to be an ideal cipher anymore, but observes a distinguishing property i.e., an explicit relation verified by all its inputs and outputs. As a consequence of this extended proof, all known distinguishers for the keyed permutation are proven not to weaken the security of Shabal. In our study, we provide the foundation of a generalization of the indifferentiability framework to biased random primitives, this part being of independent interest.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
Recommended security parameters: (p,r)='''(3,12)'''&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the hash function according to the NIST requirements. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| || || || || ||&lt;br /&gt;
|-                    &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks). &lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|   Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|   | non-randomness&amp;lt;sup&amp;gt;(1)&amp;lt;/sup&amp;gt; || permutation || all || || 2&amp;lt;sup&amp;gt;12&amp;lt;/sup&amp;gt; || || [http://131002.net/data/papers/Aum09.pdf Aumasson]&lt;br /&gt;
|-                                              &lt;br /&gt;
|   | non-randomness&amp;lt;sup&amp;gt;(1)&amp;lt;/sup&amp;gt; || permutation || all || || 1 || || [http://www.mat.dtu.dk/people/S.Thomsen/shabal/shabal.pdf Knudsen,Matusiewicz,Thomsen]&lt;br /&gt;
|-  &lt;br /&gt;
|   | non-randomness&amp;lt;sup&amp;gt;(1)&amp;lt;/sup&amp;gt; || permutation || all || || 2 || || [http://131002.net/data/papers/AMM09.pdf Aumasson,Mashatan,Meier]&lt;br /&gt;
|-                                           &lt;br /&gt;
|   | non-randomness || permutation || all || || 2&amp;lt;sup&amp;gt;159&amp;lt;/sup&amp;gt; || || [http://gva.noekeon.org/papers/ShabalRotation.pdf Van Assche]&lt;br /&gt;
|-                                           &lt;br /&gt;
|   | non-randomness || permutation || all || || 2&amp;lt;sup&amp;gt;21&amp;lt;/sup&amp;gt; || || [http://eprint.iacr.org/2010/398.pdf Novotney]&lt;br /&gt;
|-                                           &lt;br /&gt;
|}                    &lt;br /&gt;
&amp;lt;sup&amp;gt;(1)&amp;lt;/sup&amp;gt;The Shabal team commented on these analyses and provide an update of their security proofs in [http://eprint.iacr.org/2009/199.pdf this note].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalAum09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson},&lt;br /&gt;
  title     = {On the pseudorandomness of Shabal's keyed permutation},&lt;br /&gt;
  url        = {http://131002.net/data/papers/Aum09.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  abstract = {&lt;br /&gt;
  We report observations suggesting that the permutation used in&lt;br /&gt;
  Shabal does not behave pseudorandomly. This does not affect the&lt;br /&gt;
  security of Shabal as submitted to the NIST Hash Competition.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalKMT09,&lt;br /&gt;
  author    = {Lars R. Knudsen and Krystian Matusiewicz and Søren S. Thomsen},&lt;br /&gt;
  title     = {Observations on the Shabal keyed permutation},&lt;br /&gt;
  url        = {http://www.mat.dtu.dk/people/S.Thomsen/shabal/shabal.pdf },&lt;br /&gt;
  howpublished = {OFFICIAL COMMENT},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  abstract = {&lt;br /&gt;
 In this note we show that the permutation P used in the Shabal hash function, which is&lt;br /&gt;
a candidate in the SHA-3 competition, has some non-random properties. As an example,&lt;br /&gt;
it is easy to find a number of fixed points in the permutation. Moreover, large key-multicollisions&lt;br /&gt;
can be easily found; these are multi-collisions where only the key input contains&lt;br /&gt;
a difference. All observations are easily verified, and most of them are independent of the&lt;br /&gt;
choice of security parameters. Our observations, on the other hand, do not seem extensible&lt;br /&gt;
to the full hash function.&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalAum09a,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Atefeh Mashatan and Willi Meier},&lt;br /&gt;
  title     = {More on Shabal's permutation},&lt;br /&gt;
  url        = {http://131002.net/data/papers/AMM09.pdf},&lt;br /&gt;
  howpublished = {OFFICIAL COMMENT},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalVA10,&lt;br /&gt;
  author    = {Gilles Van Assche},&lt;br /&gt;
  title     = {A rotational distinguisher on Shabal's keyed permutation and its impact on the security proofs},&lt;br /&gt;
  url        = {http://gva.noekeon.org/papers/ShabalRotation.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2010},&lt;br /&gt;
  abstract = {In this short note, we apply a rotational distinguisher to the keyed permutation of the SHA-3 candidate Shabal. We then discuss its applicability in the scope of Shabal's mode of operation and its impact on the security proofs.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalNov10,&lt;br /&gt;
    author = {Peter Novotney},&lt;br /&gt;
    title = {Distinguisher for Shabal's Permutation Function},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2010/398},&lt;br /&gt;
    year = {2010},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
  abstract = {In this note we consider the Shabal permutation function $\mathcal{P}$ as a block cipher with input $A_p$,$B_p$ and key $C$,$M$ and describe a distinguisher with a data complexity of $2^{23}$ random inputs with a given difference. If the attacker can control one chosen bit of $B_p$, only $2^{21}$ inputs with a given difference are required on average. This distinguisher does not appear to lead directly to an attack on the full Shabal construction. },&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Fugue&amp;diff=3516</id>
		<title>Fugue</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Fugue&amp;diff=3516"/>
		<updated>2010-06-21T11:10:20Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Added Aumasson/Phan distinguisher of output transformation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Shai Halevi and William E. Hall and Charanjit S. Jutla&lt;br /&gt;
* Website: [http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html  http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html]&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** round 1/2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Fugue_Round2_Update.zip Fugue_Round2_Update.zip] (old versions: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Fugue.zip Fugue.zip], [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/FugueUpdate.zip FugueUpdate.zip], [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Fugue_Round2.zip Fugue_Round2.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Halevi09,&lt;br /&gt;
  author    = {Shai Halevi and William E. Hall and Charanjit S. Jutla},&lt;br /&gt;
  title     = {The Hash Function Fugue},&lt;br /&gt;
  url        = {http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html/$FILE/fugue_09.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (updated)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Halevi08,&lt;br /&gt;
  author    = {Shai Halevi and William E. Hall and Charanjit S. Jutla},&lt;br /&gt;
  title     = {The Hash Function Fugue},&lt;br /&gt;
  url        = {http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html/$FILE/NIST-submission-Oct08-fugue.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
Recommended security parameters: (k,r,t) = '''(2,5,13)''' for (n=224,256); (k,r,t) = '''(3,5,13)''' for (n=384); (k,r,t) = '''(4,8,13)''' for (n=512)&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the hash function according to the NIST requirements. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-&lt;br /&gt;
| || |||| || ||         &lt;br /&gt;
|-            &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks).&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                   &lt;br /&gt;
| distinguisher&amp;lt;sup&amp;gt;(1)&amp;lt;/sup&amp;gt; || output transformation || 256 ||    || 1  || - || [http://ehash.iaik.tugraz.at/uploads/c/cd/Fugue_path.pdf Aumasson,Phan]&lt;br /&gt;
|-                   &lt;br /&gt;
| internal collision || hash function || 256 || (2,5,13)   || 2&amp;lt;sup&amp;gt;352&amp;lt;/sup&amp;gt;  || 2&amp;lt;sup&amp;gt;352&amp;lt;/sup&amp;gt; || [http://cryptolux.org/mediawiki/uploads/9/99/Struct2.pdf Khovratovich]&lt;br /&gt;
|-&lt;br /&gt;
| internal collision || hash function || 512 || (4,8,13)   || 2&amp;lt;sup&amp;gt;480&amp;lt;/sup&amp;gt;  || 2&amp;lt;sup&amp;gt;480&amp;lt;/sup&amp;gt; || [http://cryptolux.org/mediawiki/uploads/9/99/Struct2.pdf Khovratovich]&lt;br /&gt;
|-                    &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;(1)&amp;lt;/sup&amp;gt;The Fugue team commented on these distinguishers in [http://ehash.iaik.tugraz.at/uploads/d/d7/Fugue_designers_reply_to_AumassonPhan_Distinguisher.txt this note] using [http://ehash.iaik.tugraz.at/uploads/c/c8/Fig7.pdf this figure].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{nistAP10,&lt;br /&gt;
    author = {Jean-Philippe Aumasson and Raphael C.-W. Phan},&lt;br /&gt;
    title = {Analysis of Fugue-256},&lt;br /&gt;
    howpublished = {Posting to NIST hash mailing list},&lt;br /&gt;
    year = {2010},&lt;br /&gt;
    url = {http://ehash.iaik.tugraz.at/uploads/c/cd/Fugue_path.pdf},&lt;br /&gt;
    abstract = {We would like to report our analysis results on the final round algorithm of&lt;br /&gt;
Fugue-256 (i.e., the function called &amp;quot;G&amp;quot;):&lt;br /&gt;
&lt;br /&gt;
The attached pdf note shows an example differential characteristic of&lt;br /&gt;
probability 1, on 15 intermediate rounds of G, as well as an extended&lt;br /&gt;
characteristic that can be used as a distinguisher for the full&lt;br /&gt;
18-round G. It also shows how differences propagate on an&lt;br /&gt;
augmented-round version of G (i.e. if more G2 rounds were added).&lt;br /&gt;
&lt;br /&gt;
A detailed analysis as well as further observations will be reported&lt;br /&gt;
in a subsequent paper.&lt;br /&gt;
},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sacKhovratovich09,&lt;br /&gt;
    author = {Dmitry Khovratovich},&lt;br /&gt;
    title = {Cryptanalysis of hash functions with structures},&lt;br /&gt;
    howpublished = {Proceedings of Selected Areas in Cryptography},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    url = {http://cryptolux.org/mediawiki/uploads/9/99/Struct2.pdf},&lt;br /&gt;
    abstract = {Hash function cryptanalysis has acquired many methods,&lt;br /&gt;
tools and tricks from other areas, mostly block ciphers. In this paper&lt;br /&gt;
another trick from block cipher cryptanalysis, the structures, is used for&lt;br /&gt;
speeding up the collision search. We investigate the memory and the time&lt;br /&gt;
complexities of this approach under different assumptions on the round&lt;br /&gt;
functions. The power of the new attack is illustrated with the crypt-&lt;br /&gt;
analysis of the hash functions Grindahl and the analysis of the SHA-3&lt;br /&gt;
candidate Fugue (both functions as 256 and 512 bit versions). The collision attack on Grindahl-512 is the first collision attack on this function.&lt;br /&gt;
},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Fugue_designers_reply_to_AumassonPhan_Distinguisher.txt&amp;diff=3515</id>
		<title>File:Fugue designers reply to AumassonPhan Distinguisher.txt</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Fugue_designers_reply_to_AumassonPhan_Distinguisher.txt&amp;diff=3515"/>
		<updated>2010-06-21T11:05:06Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Fig7.pdf&amp;diff=3514</id>
		<title>File:Fig7.pdf</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Fig7.pdf&amp;diff=3514"/>
		<updated>2010-06-21T11:04:10Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Fugue_path.pdf&amp;diff=3513</id>
		<title>File:Fugue path.pdf</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Fugue_path.pdf&amp;diff=3513"/>
		<updated>2010-06-21T10:56:48Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Fugue&amp;diff=3427</id>
		<title>Fugue</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Fugue&amp;diff=3427"/>
		<updated>2010-04-12T15:52:51Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added SAC2009 paper&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Shai Halevi and William E. Hall and Charanjit S. Jutla&lt;br /&gt;
* Website: [http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html  http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html]&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** round 1/2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Fugue_Round2_Update.zip Fugue_Round2_Update.zip] (old versions: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Fugue.zip Fugue.zip], [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/FugueUpdate.zip FugueUpdate.zip], [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Fugue_Round2.zip Fugue_Round2.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Halevi09,&lt;br /&gt;
  author    = {Shai Halevi and William E. Hall and Charanjit S. Jutla},&lt;br /&gt;
  title     = {The Hash Function Fugue},&lt;br /&gt;
  url        = {http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html/$FILE/fugue_09.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (updated)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Halevi08,&lt;br /&gt;
  author    = {Shai Halevi and William E. Hall and Charanjit S. Jutla},&lt;br /&gt;
  title     = {The Hash Function Fugue},&lt;br /&gt;
  url        = {http://domino.research.ibm.com/comm/research_projects.nsf/pages/fugue.index.html/$FILE/NIST-submission-Oct08-fugue.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the hash function according to the NIST requirements. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
Recommended security parameters: (k,r,t) = '''(2,5,13)''' for (n=224,256); (k,r,t) = '''(3,5,13)''' for (n=384); (k,r,t) = '''(4,8,13)''' for (n=512)&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| internal collision || 256 || (2,5,13)   || 2&amp;lt;sup&amp;gt;352&amp;lt;/sup&amp;gt;  || 2&amp;lt;sup&amp;gt;352&amp;lt;/sup&amp;gt; || [http://cryptolux.org/mediawiki/uploads/9/99/Struct2.pdf Khovratovich]&lt;br /&gt;
|-&lt;br /&gt;
| internal collision || 512 || (4,8,13)   || 2&amp;lt;sup&amp;gt;480&amp;lt;/sup&amp;gt;  || 2&amp;lt;sup&amp;gt;480&amp;lt;/sup&amp;gt; || [http://cryptolux.org/mediawiki/uploads/9/99/Struct2.pdf Khovratovich]&lt;br /&gt;
|-&lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks).&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| || || || || || ||&lt;br /&gt;
|-                    &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sacKhovratovich09,&lt;br /&gt;
    author = {Dmitry Khovratovich},&lt;br /&gt;
    title = {Cryptanalysis of hash functions with structures},&lt;br /&gt;
    howpublished = {Proceedings of Selected Areas in Cryptography},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    url = {http://cryptolux.org/mediawiki/uploads/9/99/Struct2.pdf},&lt;br /&gt;
    abstract = {Hash function cryptanalysis has acquired many methods,&lt;br /&gt;
tools and tricks from other areas, mostly block ciphers. In this paper&lt;br /&gt;
another trick from block cipher cryptanalysis, the structures, is used for&lt;br /&gt;
speeding up the collision search. We investigate the memory and the time&lt;br /&gt;
complexities of this approach under different assumptions on the round&lt;br /&gt;
functions. The power of the new attack is illustrated with the crypt-&lt;br /&gt;
analysis of the hash functions Grindahl and the analysis of the SHA-3&lt;br /&gt;
candidate Fugue (both functions as 256 and 512 bit versions). The collision attack on Grindahl-512 is the first collision attack on this function.&lt;br /&gt;
},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Hamsi&amp;diff=3385</id>
		<title>Hamsi</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Hamsi&amp;diff=3385"/>
		<updated>2010-02-15T19:04:41Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: New result on Hamsi: Message Recovery and Pseudo-Preimage Attacks on the Compression Function of Hamsi-256&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Özgül Kücük&lt;br /&gt;
* Website: [http://homes.esat.kuleuven.be/~okucuk/hamsi/ http://homes.esat.kuleuven.be/~okucuk/hamsi/]&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
**round 1/2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Hamsi_Round2.zip Hamsi_Round2.zip] (old versions: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Hamsi.zip Hamsi.zip], [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/HamsiUpdate.zip HamsiUpdate.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Kucuk09,&lt;br /&gt;
  author    = {Özgül Kücük},&lt;br /&gt;
  title     = {The Hash Function Hamsi},&lt;br /&gt;
  url        = {http://www.cosic.esat.kuleuven.be/publications/article-1203.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (updated)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Kucuk08,&lt;br /&gt;
  author    = {Özgül Kücük},&lt;br /&gt;
  title     = {The Hash Function Hamsi},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/9/95/Hamsi.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
Recommended security parameters: '''(3,6)''' P,P&amp;lt;sub&amp;gt;f&amp;lt;/sub&amp;gt; rounds (n=224,256); '''(6,12)''' P,P&amp;lt;sub&amp;gt;f&amp;lt;/sub&amp;gt; rounds (n=384,512).&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the actual hash function. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| || || || || || ||&lt;br /&gt;
|-                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks). &lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|   Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-&lt;br /&gt;
|   | non-randomness || compression function || 224, 256 || 5 rounds ||  ||  || [http://ehash.iaik.tugraz.at/uploads/d/db/Hamsi_nonrandomness.txt Aumasson]&lt;br /&gt;
|-&lt;br /&gt;
|   | near-collision || compression function || 224, 256 || 3 rounds || 2&amp;lt;sup&amp;gt;21&amp;lt;/sup&amp;gt; ||  || [http://rump2009.cr.yp.to/936779b3afb9b48a404b487d6865091d.pdf Nikolic]&lt;br /&gt;
|-&lt;br /&gt;
|   | distinguisher || compression function || 224, 256 || 6 rounds || 2&amp;lt;sup&amp;gt;27&amp;lt;/sup&amp;gt; ||  || [http://www.131002.net/data/papers/AM09.pdf Aumasson,Meier]&lt;br /&gt;
|-&lt;br /&gt;
|   | distinguisher || compression function || 384, 512 || 12 rounds || 2&amp;lt;sup&amp;gt;729&amp;lt;/sup&amp;gt; ||  || [http://www.131002.net/data/papers/AM09.pdf Aumasson,Meier]&lt;br /&gt;
|-&lt;br /&gt;
|   | near-collision || compression function || 224, 256 || 3 rounds || 2&amp;lt;sup&amp;gt;5&amp;lt;/sup&amp;gt; ||  || [http://eprint.iacr.org/2009/484.pdf Wang,Wang,Jia,Wang]&lt;br /&gt;
|-&lt;br /&gt;
|   | near-collision || compression function || 224, 256 || 4 rounds || 2&amp;lt;sup&amp;gt;32&amp;lt;/sup&amp;gt; ||  || [http://eprint.iacr.org/2009/484.pdf Wang,Wang,Jia,Wang]&lt;br /&gt;
|-&lt;br /&gt;
|   | near-collision || compression function || 224, 256 || 5 rounds || 2&amp;lt;sup&amp;gt;125&amp;lt;/sup&amp;gt; ||  || [http://eprint.iacr.org/2009/484.pdf Wang,Wang,Jia,Wang]&lt;br /&gt;
|-&lt;br /&gt;
|   | message-recovery || compression function || 224, 256 || 3 rounds || 2&amp;lt;sup&amp;gt;10.48&amp;lt;/sup&amp;gt; ||  || [http://eprint.iacr.org/2010/057.pdf Calik,Turan]&lt;br /&gt;
|-&lt;br /&gt;
|   | pseudo-2nd-preimage || hash function || 256 || (3,6) rounds || 2&amp;lt;sup&amp;gt;254.25&amp;lt;/sup&amp;gt; ||  || [http://eprint.iacr.org/2010/057.pdf Calik,Turan]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{hamsiAum09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson},&lt;br /&gt;
  title     = {On the pseudorandomness of Hamsi},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/d/db/Hamsi_nonrandomness.txt},&lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{hamsiN09,&lt;br /&gt;
  author    = {Ivica Nikolic},&lt;br /&gt;
  title     = {Near Collisions for the Compression Function of Hamsi-256},&lt;br /&gt;
  url        = {http://rump2009.cr.yp.to/936779b3afb9b48a404b487d6865091d.pdf},&lt;br /&gt;
  howpublished = {CRYPTO rump session},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{hamsiAM9,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Willi Meier},&lt;br /&gt;
  title     = {Zero-sum distinguishers for reduced Keccak-f and for the core functions of Luffa and Hamsi},&lt;br /&gt;
  url        = {http://www.131002.net/data/papers/AM09.pdf},&lt;br /&gt;
  howpublished = {NIST mailing list},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  abstract  = {We present a new type of distinguisher, called zero-sum distinguisher, and apply it to reduced versions of the Keccak-f permutation. We obtain practical and deterministic distinguishers on up to 9 rounds, and shortcut distinguishers on up to 16 rounds, out of 18 in total. These observations do not seem to affect the security of Keccak. We also briefly describe application of zero-sum distinguishers to the core permutations of Luffa and Hamsi.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{hamsiWWJW09,&lt;br /&gt;
    author = {Meiqin Wang, Xiaoyun Wang, Keting Jia, Wei Wang},&lt;br /&gt;
    title = {New Pseudo-Near-Collision Attack on Reduced-Round of Hamsi-256},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/484},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/484.pdf},&lt;br /&gt;
    abstract = {Hamsi-256 is designed by Özgül Kücük and it has been a candidate Hash function for the second round of SHA-3. The compression function of Hamsi-256 maps a 256-bit chaining value and a 32-bit message to a new 256-bit chaining value. As hashing a message, Hamsi-256 operates 3-round except for the last message it operates 6-round. In this paper, we will give the pseudo-near-collision for 5-round Hamsi-256. By the message modifying, the pseudo-near-collision for 3, 4 and 5 rounds can be found with $2^5$, $2^{32}$ and $2^{125}$ compression function computations respectively.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{hamsiWWJW09,&lt;br /&gt;
    author = {Cagdas Calik and Meltem Sonmez Turan},&lt;br /&gt;
    title = {Message Recovery and Pseudo-Preimage Attacks on the Compression Function of Hamsi-256},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2010/057}},&lt;br /&gt;
    year = {2010},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
    url = {http://eprint.iacr.org/2010/057.pdf},&lt;br /&gt;
    abstract = {Hamsi is one of the second round candidates of the SHA-3&lt;br /&gt;
competition. In this study, we present non-random differential proper-&lt;br /&gt;
ties for the compression function of the hash function Hamsi-256. Based&lt;br /&gt;
on these properties, we first demonstrate a distinguishing attack that&lt;br /&gt;
requires a few evaluations of the compression function and extend the&lt;br /&gt;
distinguisher to 5 rounds with complexity 2^83 . Then, we present a mes-&lt;br /&gt;
sage recovery attack with complexity of 2^10.48 compression function evaluations. Also, we present a pseudo-preimage attack for the compression&lt;br /&gt;
function with complexity 2^254.25 . The pseudo-preimage attack on the&lt;br /&gt;
compression function is easily converted to a pseudo second preimage&lt;br /&gt;
attack on Hamsi-256 hash function with the same complexity.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=ECHO&amp;diff=3383</id>
		<title>ECHO</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=ECHO&amp;diff=3383"/>
		<updated>2010-02-15T16:15:47Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Ryad Benadjila, Olivier Billet, Henri Gilbert, Gilles Macario-Rat, Thomas Peyrin, Matt Robshaw, Yannick Seurin &lt;br /&gt;
* Website: http://crypto.rd.francetelecom.com/echo/&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** round 1/2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/ECHO_Round2.zip ECHO_Round2.zip] (old version [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/ECHO.zip ECHO.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3BBG+09,&lt;br /&gt;
  author    = {Ryad Benadjila and Olivier Billet and Henri Gilbert and Gilles Macario-Rat and Thomas Peyrin and Matt Robshaw and Yannick Seurin},&lt;br /&gt;
  title     = {SHA-3 Proposal: ECHO},&lt;br /&gt;
  url        = {http://crypto.rd.francetelecom.com/echo/doc/echo_description_1-5.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (updated)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3BBG+08,&lt;br /&gt;
  author    = {Ryad Benadjila and Olivier Billet and Henri Gilbert and Gilles Macario-Rat and Thomas Peyrin and Matt Robshaw and Yannick Seurin},&lt;br /&gt;
  title     = {SHA-3 Proposal: ECHO},&lt;br /&gt;
  url        = {http://crypto.rd.francetelecom.com/echo/doc/echo_description.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the hash function according to the NIST requirements. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
Recommended security parameters: '''8''' rounds (n=224,256); '''10''' rounds (n=384,512)&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| || || || || ||&lt;br /&gt;
|-                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks). &lt;br /&gt;
&lt;br /&gt;
Recommended security parameters: '''8''' rounds (n=224,256); '''10''' rounds (n=384,512)&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| distinguisher || permutation || all || 8 rounds || 2&amp;lt;sup&amp;gt;768&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;512&amp;lt;/sup&amp;gt; || [http://eprint.iacr.org/2009/531.pdf Gilbert,Peyrin]&lt;br /&gt;
|-                    &lt;br /&gt;
| distinguisher || permutation || all || 7 rounds || 2&amp;lt;sup&amp;gt;384&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;64&amp;lt;/sup&amp;gt; || [http://online.tu-graz.ac.at/tug_online/voe_main2.getVollText?pDocumentNr=110408 Mendel,Peyrin,Rechberger,Schläffer]&lt;br /&gt;
|-                    &lt;br /&gt;
|}  &lt;br /&gt;
&lt;br /&gt;
               &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{fseGP10,&lt;br /&gt;
  author    = {Henri Gilbert and Thomas Peyrin},&lt;br /&gt;
  title     = {Super-Sbox Cryptanalysis: Improved Attacks for AES-like permutations},&lt;br /&gt;
  url = {http://eprint.iacr.org/2009/531.pdf},&lt;br /&gt;
  booktitle  = {FSE},&lt;br /&gt;
  year       = {2010},&lt;br /&gt;
  series     = {LNCS},&lt;br /&gt;
  note = {To appear}&lt;br /&gt;
  abstract = {In this paper, we improve the recent rebound and start-from-the-middle attacks on AES-like permutations. Our new cryptanalysis technique uses the fact that one can view two rounds of such permutations as a layer of big Sboxes preceded and followed by simple affine transformations. The big Sboxes encountered in this alternative representation are named Super-Sboxes. We apply this method to two second-round SHA-3 candidates Grostl and ECHO, and obtain improvements over the previous cryptanalysis results for these two schemes. Moreover, we improve the best distinguisher for the AES block cipher in the known-key setting, reaching 8 rounds for the 128-bit version.}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{sacMPRS09,&lt;br /&gt;
  author    = {Florian Mendel and Thomas Peyrin and Christian&lt;br /&gt;
Rechberger and Martin Schläffer},&lt;br /&gt;
  title     = {Improved Cryptanalysis of the Reduced Grøstl&lt;br /&gt;
Compression Function, ECHO Permutation and AES Block Cipher},&lt;br /&gt;
  url = {http://online.tu-graz.ac.at/tug_online/voe_main2.getVollText?pDocumentNr=124407&amp;amp;pCurrPk=44420},&lt;br /&gt;
  booktitle  = {SAC},&lt;br /&gt;
  year       = {2009},&lt;br /&gt;
  volume    = {5867},&lt;br /&gt;
  pages     = {16-35},&lt;br /&gt;
  abstract = {In this paper, we propose two new ways to mount attacks&lt;br /&gt;
on the SHA-3 candidates Gr{\o}stl, and ECHO, and apply these attacks&lt;br /&gt;
also to the AES. Our results improve upon and extend the rebound&lt;br /&gt;
attack. Using the new techniques, we are able to extend the number of&lt;br /&gt;
rounds in which available degrees of freedom can be used. As a result,&lt;br /&gt;
we present the first attack on 7 rounds for the Gr{\o}stl-256 output&lt;br /&gt;
transformation and improve the semi-free-start collision attack on 6&lt;br /&gt;
rounds. Further, we present an improved known-key distinguisher for 7&lt;br /&gt;
rounds of the AES block cipher and the internal permutation used in&lt;br /&gt;
ECHO.}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Skein&amp;diff=3382</id>
		<title>Skein</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Skein&amp;diff=3382"/>
		<updated>2010-02-15T16:01:44Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added rotational attack on reduced threefish&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Niels Ferguson, Stefan Lucks, Bruce Schneier, Doug Whiting, Mihir Bellare, Tadayoshi Kohno, Jon Callas, Jesse Walker&lt;br /&gt;
* Website: [http://www.schneier.com/skein.html http://www.schneier.com/skein.html]; [http://skein-hash.info/ http://skein-hash.info/]&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** round 1: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/SkeinUpdate.zip SkeinUpdate.zip] (old version: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Skein.zip Skein.zip])&lt;br /&gt;
** round 2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/Skein_Round2.zip Skein_Round2.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3F+09,&lt;br /&gt;
  author    = {Niels Ferguson and Stefan Lucks and Bruce Schneier and Doug Whiting and Mihir Bellare and Tadayoshi Kohno and Jon Callas and Jesse Walker},&lt;br /&gt;
  title     = {The Skein Hash Function Family},&lt;br /&gt;
  url        = {http://www.skein-hash.info/sites/default/files/skein1.2.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (Round 2)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3F+08,&lt;br /&gt;
  author    = {Niels Ferguson and Stefan Lucks and Bruce Schneier and Doug Whiting and Mihir Bellare and Tadayoshi Kohno and Jon Callas and Jesse Walker},&lt;br /&gt;
  title     = {The Skein Hash Function Family},&lt;br /&gt;
  url        = {http://www.skein-hash.info/sites/default/files/skein.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST (Round 1)},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.&lt;br /&gt;
&lt;br /&gt;
A description of the tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
Recommended security parameter: '''72''' rounds (n=256,512)&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on the hash function according to the NIST requirements. The only allowed modification is to change the security parameter.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| || || || || ||&lt;br /&gt;
|-                    &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Building blocks ===&lt;br /&gt;
&lt;br /&gt;
Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.&lt;br /&gt;
&lt;br /&gt;
Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks). &lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-&lt;br /&gt;
|-     &lt;br /&gt;
|  near collision || compression function || 512 || 17 rounds (Round 1) || 2&amp;lt;sup&amp;gt;24&amp;lt;/sup&amp;gt; || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|-     &lt;br /&gt;
|  distinguisher || block cipher || 512 || 35 rounds (Round 1) || 2&amp;lt;sup&amp;gt;478&amp;lt;/sup&amp;gt; || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|- &lt;br /&gt;
|  impossible differential || block cipher || 512 || 21 rounds (Round 1) || - || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|-        &lt;br /&gt;
|  key recovery || block cipher || 512 || 32 rounds (Round 1) || 2&amp;lt;sup&amp;gt;312&amp;lt;/sup&amp;gt; || - || [http://eprint.iacr.org/2009/438.pdf Aumasson,Calik,Meier,Ozen,Phan,Varici]&lt;br /&gt;
|-    &lt;br /&gt;
|  key recovery || block cipher || 512 || 32 rounds (Round 1) || 2&amp;lt;sup&amp;gt;226&amp;lt;/sup&amp;gt; (2&amp;lt;sup&amp;gt;222&amp;lt;/sup&amp;gt;) || 2&amp;lt;sup&amp;gt;12&amp;lt;/sup&amp;gt; || [http://eprint.iacr.org/2009/526.pdf Chen,Jia]&lt;br /&gt;
|-  &lt;br /&gt;
|  key recovery || block cipher || 512 || 33 rounds (Round 1) || 2&amp;lt;sup&amp;gt;352.17&amp;lt;/sup&amp;gt; (2&amp;lt;sup&amp;gt;355.5&amp;lt;/sup&amp;gt;) || - || [http://eprint.iacr.org/2009/526.pdf Chen,Jia]&lt;br /&gt;
|-&lt;br /&gt;
|  key recovery || block cipher || 256 || 39 rounds || 2&amp;lt;sup&amp;gt;254.1&amp;lt;/sup&amp;gt; || - || [https://cryptolux.org/mediawiki/uploads/5/5b/Rotational_Cryptanalysis_of_Skein.pdf Khovratovich,Nikolic]&lt;br /&gt;
|-&lt;br /&gt;
|  key recovery || block cipher || 512 || 42 rounds|| 2&amp;lt;sup&amp;gt;507&amp;lt;/sup&amp;gt; || - || [https://cryptolux.org/mediawiki/uploads/5/5b/Rotational_Cryptanalysis_of_Skein.pdf Khovratovich,Nikolic]&lt;br /&gt;
|-&lt;br /&gt;
|}        &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{skeinA+09,&lt;br /&gt;
    author = {Jean-Philippe Aumasson and Cagdas Calik and Willi Meier and Onur Ozen and Raphael C.-W. Phan and Kerem Varici},&lt;br /&gt;
    title = {Improved Cryptanalysis of Skein},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/438},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/438.pdf},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
    abstract={The hash function Skein is the submission of Ferguson et al. to the NIST Hash Competition, and is arguably a serious candidate for selection as SHA-3. This paper presents the first third-party analysis of Skein, with an extensive study of its main component: the block cipher Threefish. We notably investigate near collisions, distinguishers, impossible differentials, key recovery using related-key differential and boomerang attacks. In particular, we present near collisions on up to 17 rounds, an impossible differential on 21 rounds, a related-key boomerang distinguisher on 34 rounds, a known-related-key boomerang distinguisher on 35 rounds, and key recovery attacks on up to 32 rounds, out of 72 in total for Threefish-512. None of our attacks directly extends to the full Skein hash. However, the pseudorandomness of Threefish is required to validate the security proofs on Skein, and our results conclude that at least 36 rounds of Threefish seem required for optimal security guarantees.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cryptoeprint:2009:526,&lt;br /&gt;
    author = {Jiazhe Chen and Keting Jia},&lt;br /&gt;
    title = {Improved Related-key Boomerang Attacks on Round-Reduced Threefish-512},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/526},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/526.pdf},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
    abstract = {Hash function Skein is one of the 14 NIST SHA-3 second round candidates. Threefish is a tweakable block cipher as the core of Skein, defined with a 256-, 512-, and 1024-bit block size. The 512-bit block size is the primary proposal of the authors. In this paper we construct two related-key boomerang distinguishers on round-reduced Threefish-512 using the method of \emph{modular differential}. With a distinguisher on 32 rounds of Threefish-512, we improve the key recovery attack on 32 rounds of Threefish-512 proposed by Aumasson et al. Their attack requires $2^{312}$ encryptions and $2^{71}$ bytes of memory. However, our attack has a time complexity of $2^{226}$ encryptions with memory of $2^{12}$ bytes. Furthermore, we give a key recovery attack on Threefish-512 reduced to 33 rounds using a 33-round related-key boomerang distinguisher, with $2^{352.17}$ encryptions and negligible memory. Skein had been updated after it entered the second round and the results above are based on the original version. However, as the only differences between the original and the new version are the rotation constants, both of the methods can be applied to the new version with modified differential trails. For the new rotation constants, our attack on 32-round Threefish-512 has a time complexity $2^{222}$ and $2^{12}$ bytes' memory. Our attack on 33-round Threefish-512 has a time complexity $2^{355.5}$ and negligible memory.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cryptoeprint:2009:526,&lt;br /&gt;
    author = {Dmitry Khovratovich and Ivica Nikolic},&lt;br /&gt;
    title = {Rotational Cryptanalysis of ARX},&lt;br /&gt;
    howpublished = {Preproceedings of FSE 2010},&lt;br /&gt;
    year = {2010},&lt;br /&gt;
    url = {https://cryptolux.org/mediawiki/uploads/5/5b/Rotational_Cryptanalysis_of_Skein.pdf},&lt;br /&gt;
    abstract = {In this paper we analyze the security of systems based on&lt;br /&gt;
modular additions, rotations, and XORs (ARX systems). We provide&lt;br /&gt;
both theoretical support for their security and practical cryptanalysis of&lt;br /&gt;
real ARX primitives. We use a technique called rotational cryptanalysis,&lt;br /&gt;
that is universal for the ARX systems and is quite efficient. We illustrate&lt;br /&gt;
the method with the best known attack on reduced versions of the block&lt;br /&gt;
cipher Threeﬁsh (the core of Skein). Additionally, we prove that ARX&lt;br /&gt;
with constants are functionally complete, i.e. any function can be realized&lt;br /&gt;
with these operations.&lt;br /&gt;
},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Archive ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{SkeinAum09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Willi Meier and Raphael Phan},&lt;br /&gt;
  title     = {Improved analyis of Threefish},&lt;br /&gt;
  url = {http://131002.net/data/talks/threefish_rump.pdf},&lt;br /&gt;
  howpublished = {FSE 2009 rump session, slides available online},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=BLAKE&amp;diff=3313</id>
		<title>BLAKE</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=BLAKE&amp;diff=3313"/>
		<updated>2010-01-28T14:40:58Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: split tables template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Jean-Philippe Aumasson, Luca Henzen, Willi Meier, Raphael C.-W. Phan&lt;br /&gt;
* Website: [http://131002.net/blake/ http://131002.net/blake/]&lt;br /&gt;
* NIST submission package: &lt;br /&gt;
** round 1/2: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round2/documents/BLAKE_Round2.zip BLAKE_Round2.zip] (old versions: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/BLAKE.zip BLAKE.zip], [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/BLAKEUpdate.zip BLAKEUpdate.zip])&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3AumassonHMP08,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Luca Henzen and Willi Meier and Raphael C.-W. Phan},&lt;br /&gt;
  title     = {SHA-3 proposal BLAKE},&lt;br /&gt;
  url        = {http://131002.net/blake/blake.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
We distinguish between two cases: results on the complete hash function, and results on the building blocks.&lt;br /&gt;
A description of these tables is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
=== Hash function ===&lt;br /&gt;
Here we list results on the actual hash function. The only allowed modification is to change the security parameter.&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis ||  Hash Size (n) || Parameters || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| preimage || 224,256 || 2.5/10 rounds   || 2&amp;lt;sup&amp;gt;n-15&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2009/238.pdf Ji,Liangyu]&lt;br /&gt;
|-&lt;br /&gt;
| preimage || 384 || 2.5/10 rounds   || 2&amp;lt;sup&amp;gt;355&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2009/238.pdf Ji,Liangyu]&lt;br /&gt;
|-&lt;br /&gt;
| preimage ||  512 || 2.5/10 rounds  || 2&amp;lt;sup&amp;gt;481&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2009/238.pdf Ji,Liangyu]&lt;br /&gt;
|-&lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
=== Underlying building blocks ===&lt;br /&gt;
Here we list results that assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks). &lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| free-start collision || hash || 224,256 || 2.5/10 rounds  || 2&amp;lt;sup&amp;gt;n/2-16&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2009/238.pdf Ji,Liangyu]&lt;br /&gt;
|-&lt;br /&gt;
| free-start collision || hash || 384,512 || 2.5/10 rounds  || 2&amp;lt;sup&amp;gt;n/2-32&amp;lt;/sup&amp;gt;  || - || [http://eprint.iacr.org/2009/238.pdf Ji,Liangyu]&lt;br /&gt;
|-&lt;br /&gt;
| near-collision || compression function || 256 || 4/10 rounds (nb. 6-9)  || 2&amp;lt;sup&amp;gt;42&amp;lt;/sup&amp;gt;  || - || [http://www.jguo.org/docs/blake-col.pdf Guo,Matusiewicz]&lt;br /&gt;
|-&lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cryptoeprint:2009:238,&lt;br /&gt;
    author = {Li Ji and Xu Liangyu },&lt;br /&gt;
    title = {Attacks on Round-Reduced BLAKE},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/238},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/238.pdf},&lt;br /&gt;
    abstract = {BLAKE is a new hash family proposed for SHA-3. The core of compression function reuses the core function of ChaCha. A round-dependent permutation is used as message schedule. BLAKE is claimed to achieve full diffusion after 2 rounds. However, message words can be controlled on the first several founds. By exploiting properties of message permutation, we can attack 2.5 reduced rounds. The results do not threat the security claimed in the specification. },&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{blakeGM09,&lt;br /&gt;
 author = {Jian Guo and Krystian Matusiewicz},&lt;br /&gt;
 title  = {Round-Reduced Near-Collisions of BLAKE-32},&lt;br /&gt;
 url    = {http://www.jguo.org/docs/blake-col.pdf},&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 note = {Accepted for presentation at WEWoRC 2009},&lt;br /&gt;
 year   = {2009}&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_Hash_Function_Zoo&amp;diff=3213</id>
		<title>The Hash Function Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_Hash_Function_Zoo&amp;diff=3213"/>
		<updated>2009-07-30T12:53:49Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Update on Vortex&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+'''The Hash Function Zoo, a collection of cryptographic hash functions (in alphabetical order)'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Also check out Paulo Barreto's [http://paginas.terra.com.br/informatica/paulobarreto/hflounge.html  Hash Function Lounge].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
For the recent submissions to the SHA-3 competition, there is a separate [[The_SHA-3_Zoo| SHA-3 Zoo]]&lt;br /&gt;
&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;150&amp;quot;| Hash Function Name !! Designer(s) !! Issued in !! Status Cryptanalysis&lt;br /&gt;
|-&lt;br /&gt;
| [[AR]]           || ISO || align=&amp;quot;center&amp;quot;|1992 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[Boognish]]     || Daemen || align=&amp;quot;center&amp;quot;|1992 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[Cellhash]]     || Daemen, Govaerts, Vandewalle || align=&amp;quot;center&amp;quot;|1991 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[DASH]]     || Billet, Robshaw, Seurin, Yin || align=&amp;quot;center&amp;quot;|2008 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[DHA-256]]      || Lee, Chang, Kim, Lee, Hong || align=&amp;quot;center&amp;quot;|2006 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R]]       || Gligoroski, Markovski, Kocarev || align=&amp;quot;center&amp;quot;|2006 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[FFT-Hash I]]    || Schnorr || align=&amp;quot;center&amp;quot;|1991 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[FFT-Hash II]]  || Schnorr || align=&amp;quot;center&amp;quot;|1992 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[FORK-256]]      || Hong, Chang, Sung, Lee, Hong, Lee, Moon, Chee || align=&amp;quot;center&amp;quot;|2006 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB]]          || Augot, Finiasz, Sendrier || align=&amp;quot;center&amp;quot;|2005 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[GOST | GOST 34.11-94]]         || Government Committee of Russia for Standards || align=&amp;quot;center&amp;quot;|1990 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[Grindahl-256]] || Knudsen, Rechberger, Thomsen || align=&amp;quot;center&amp;quot;|2007 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[Grindahl-512]] || Knudsen, Rechberger, Thomsen || align=&amp;quot;center&amp;quot;|2007 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[HAS-160]]      || Telecommunications Technology Association of Korea || align=&amp;quot;center&amp;quot;| 2000 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[HAS-V]]        || Park, Hwang, Lee || align=&amp;quot;center&amp;quot;|2000 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[HAVAL]]        || Zheng, Pieprzyk, Seberry || align=&amp;quot;center&amp;quot;|1994 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[LAKE]]         || Aumasson, Meier, Phan|| align=&amp;quot;center&amp;quot;|2008|| ?&lt;br /&gt;
|-&lt;br /&gt;
| [[LASH-n]]       || Bentahar, Page, Saarinen, Silverman, Smart || align=&amp;quot;center&amp;quot;|2006 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[MAME]]         || Yoshida, Watanabe, Okeya, Kitahara, Wu, Kucuk, Preneel || align=&amp;quot;center&amp;quot;|2007 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[MD2]]          || Rivest || align=&amp;quot;center&amp;quot;|1989 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[MD4]]          || Rivest || align=&amp;quot;center&amp;quot;|1990 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[MD5]]          || Rivest || align=&amp;quot;center&amp;quot;|1992 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[N-Hash]]       || Miyaguchi, Ohta, Iwata || align=&amp;quot;center&amp;quot;|1990 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[PANAMA]]       || Daemen, Clapp || align=&amp;quot;center&amp;quot;|1998 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[Parallel FFT-Hash]]  || Schnorr, Vaudenay || align=&amp;quot;center&amp;quot;|1993 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[PARSHA-256]] || Pal, Sarkar || align=&amp;quot;center&amp;quot;|2003 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[PKC-HASH]] || Shin, Rhee, Ryu, Lee || align=&amp;quot;center&amp;quot;|1998 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[RadioGatun]] || Bertoni, Daemen, Peeters, van Assche || align=&amp;quot;center&amp;quot;|2006 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[RC4-HASH]] || Chang, Gupta, Nandi || align=&amp;quot;center&amp;quot;|2006 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[RIPEMD]] || The RIPE Consortium || align=&amp;quot;center&amp;quot;|1990 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[RIPEMD-128]] || Dobbertin, Bosselaers, Preneel || align=&amp;quot;center&amp;quot;|1996 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[RIPEMD-160]] || Dobbertin, Bosselaers, Preneel || align=&amp;quot;center&amp;quot;|1996 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[SHA-0]]            || NIST/NSA || align=&amp;quot;center&amp;quot;|1991 || broken &lt;br /&gt;
|-&lt;br /&gt;
| [[SHA-1]]           || NIST/NSA || align=&amp;quot;center&amp;quot;|1993 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[SHA-256/224]]        || NIST/NSA || align=&amp;quot;center&amp;quot;|2000 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[SHA-512/384]]        || NIST/NSA || align=&amp;quot;center&amp;quot;|2000 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[SMASH]]           || Knudsen || align=&amp;quot;center&amp;quot;|2005 || broken &lt;br /&gt;
|-&lt;br /&gt;
| [[Snefru-n]]     || Merkle  || align=&amp;quot;center&amp;quot;|1990 || broken &lt;br /&gt;
|-&lt;br /&gt;
| [[StepRightUp]] || Daemen  || align=&amp;quot;center&amp;quot;|1995 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[SubHash]]       || Daemen  || align=&amp;quot;center&amp;quot;|1992 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFT]]       || Lyubashevsky, Micciancio, Peikert, Rosen || align=&amp;quot;center&amp;quot;|2008 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[Tiger]]       || Anderson, Biham  || align=&amp;quot;center&amp;quot;|1996 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[Vortex]]       || Gueron, Kounavis  || align=&amp;quot;center&amp;quot;|2008 || broken&lt;br /&gt;
|-&lt;br /&gt;
| [[VSH]]       || Contini, Lenstra, Steinfeld  || align=&amp;quot;center&amp;quot;|2005 || ?&lt;br /&gt;
|-&lt;br /&gt;
| [[Whirlpool]]   || Barreto and Rijmen || align=&amp;quot;center&amp;quot;|2000 || ?&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Regarding the column cryptanalysis status, for simplicity reasons we take the following view.&lt;br /&gt;
As soon as there are results suggesting that an expected property of a hash function is less than ideal, we list it as 'broken'. Resulting attacks may be by no means practical. &lt;br /&gt;
&lt;br /&gt;
Note that the source for most of the data collected here (proposals and analysis results) is published in one of the following venues. Journal of Cryptology, IEEE Transactions on Information Theory, proceedings of IACR conferences like Crypto, Eurocrypt, Asiacrypt, Africacrypt, FSE. Additionally also SAC, ISC, CT-RSA, PKCS, FIPS and ISO Standards are used.&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Vortex&amp;diff=3212</id>
		<title>Vortex</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Vortex&amp;diff=3212"/>
		<updated>2009-07-30T12:50:45Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Update on Vortex&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Specification ==&lt;br /&gt;
&lt;br /&gt;
* digest size: 256 bits&lt;br /&gt;
* max. message length: &amp;lt; 2&amp;lt;sup&amp;gt;64&amp;lt;/sup&amp;gt; bits&lt;br /&gt;
* compression function: 512-bit message block, 256-bit chaining variable&lt;br /&gt;
* Specification: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{iswGueronK08,&lt;br /&gt;
  author    = {Shay Gueron and Michael E. Kounavis},&lt;br /&gt;
  title     = {Vortex: A New Family of One-Way Hash Functions Based on AES Rounds and Carry-Less Multiplication},&lt;br /&gt;
  booktitle = {ISC},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  pages     = {331-340},&lt;br /&gt;
  abstract  = {We present Vortex a new family of one way hash functions that can produce message digests of 256 bits. The main idea behind the design of these hash functions is that we use well known algorithms that can support very fast diffusion in a small number of steps. We also balance the cryptographic strength that comes from iterating block cipher rounds with SBox substitution and diffusion (like Whirlpool) against the need to have a lightweight implementation with as small number of rounds as possible. We use only 3 AES rounds but with a stronger key schedule. Our goal is not to protect a secret symmetric key but to support perfect mixing of the bits of the input into the hash value. Three AES rounds are followed by our variant of Galois Field multiplication. This achieves cross-mixing between 128-bit sets. We present a set of qualitative arguments why we believe Vortex is secure.},&lt;br /&gt;
  url        = {http://dx.doi.org/10.1007/978-3-540-85886-7_23},&lt;br /&gt;
  editor    = {Tzong-Chen Wu and Chin-Laung Lei and Vincent Rijmen and Der-Tsai Lee},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  volume    = {5222},&lt;br /&gt;
  isbn      = {978-3-540-85884-3},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Best Known Results ===&lt;br /&gt;
Collision attacks and distinguishing attacks were found.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Generic Attacks ===&lt;br /&gt;
* [[GenericAttacksMerkleDamgaard| Generic Attacks on the Merkle-Damgaard Construction ]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Collision Attacks ===&lt;br /&gt;
A collision attack is described in&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{ADMRT09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Orr Dunkelman and Florian Mendel and Christian Rechberger and Søren S. Thomsen},&lt;br /&gt;
  title     = {Cryptanalysis of Vortex},&lt;br /&gt;
  booktitle = {AFRICACRYPT},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  editor = {Bart Preneel},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  pages     = {14-28},&lt;br /&gt;
  volume    = {5580},&lt;br /&gt;
  url = {http://www.131002.net/data/papers/ADMRT09.pdf},&lt;br /&gt;
  abstract = {Vortex is a hash function that was first presented at ISC’2008, then submitted to the NIST SHA-3 competition after some modifications. This paper describes several attacks on both versions of Vortex, including collisions, second preimages, preimages, and distinguishers. Our attacks exploit flaws both in the high-level design and in the lower-level algorithms.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Preimage Attacks ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Others ===&lt;br /&gt;
A distinguisher is described in&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{ADMRT09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Orr Dunkelman and Florian Mendel and Christian Rechberger and Søren S. Thomsen},&lt;br /&gt;
  title     = {Cryptanalysis of Vortex},&lt;br /&gt;
  booktitle = {AFRICACRYPT},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  editor = {Bart Preneel},&lt;br /&gt;
  series    = {LNCS},&lt;br /&gt;
  pages     = {14-28},&lt;br /&gt;
  volume    = {5580},&lt;br /&gt;
  url = {http://www.131002.net/data/papers/ADMRT09.pdf},&lt;br /&gt;
  abstract = {Vortex is a hash function that was first presented at ISC’2008, then submitted to the NIST SHA-3 competition after some modifications. This paper describes several attacks on both versions of Vortex, including collisions, second preimages, preimages, and distinguishers. Our attacks exploit flaws both in the high-level design and in the lower-level algorithms.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Lesamnta&amp;diff=3211</id>
		<title>Lesamnta</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Lesamnta&amp;diff=3211"/>
		<updated>2009-07-30T08:16:31Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Update on Lesamta&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Shoichi Hirose, Hidenori Kuwakado, Hirotaka Yoshida&lt;br /&gt;
* Website: [http://www.sdl.hitachi.co.jp/crypto/lesamnta/ http://www.sdl.hitachi.co.jp/crypto/lesamnta/]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Lesamnta.zip Lesamnta.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3HiroseKY08,&lt;br /&gt;
  author    = {Shoichi Hirose and Hidenori Kuwakado and Hirotaka Yoshida},&lt;br /&gt;
  title     = {SHA-3 Proposal: Lesamnta},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/5/5c/Lesamnta.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3HiroseKY09,&lt;br /&gt;
  author    = {Shoichi Hirose and Hidenori Kuwakado and Hirotaka Yoshida}&lt;br /&gt;
  title     = {Security Analysis of the Compression Function&lt;br /&gt;
of Lesamnta and its Impact},&lt;br /&gt;
  url = {http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/LESAMNTA_Comments.pdf},&lt;br /&gt;
  howpublished = {Official comment},&lt;br /&gt;
  year       = {2009},&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
               &lt;br /&gt;
| pseudo-collision || compression || 256 || full || O(2&amp;lt;sup&amp;gt;64&amp;lt;/sup&amp;gt;) || - || Bouillaguet, Dunkelman, Leurent, Fouque&lt;br /&gt;
|-                    &lt;br /&gt;
|}  &lt;br /&gt;
               &lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{privateHiroseKY09,&lt;br /&gt;
  author    = {C. Bouillaguet and O. Dunkelman and G. Leurent and P. A. Fouque}&lt;br /&gt;
  title     = {Personal communication},&lt;br /&gt;
  howpublished = {Cited in Shoichi Hirose, Hidenori Kuwakado, Hirotaka Yoshida: &amp;quot;Security Analysis of the Compression Function of Lesamnta and its Impact&amp;quot;},&lt;br /&gt;
  year       = {2009},&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=FSB_(SHA-3_submission)&amp;diff=3173</id>
		<title>FSB (SHA-3 submission)</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=FSB_(SHA-3_submission)&amp;diff=3173"/>
		<updated>2009-07-20T12:20:18Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Added Bernstein et al. implementation of generic attack against FSB&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Daniel Augot, Matthieu Finiasz, Philippe Gaborit, Stéphane Manuel, Nicolas Sendrier&lt;br /&gt;
* Website: [http://www-rocq.inria.fr/secret/CBCrypto/index.php?pg=fsb http://www-rocq.inria.fr/secret/CBCrypto/index.php?pg=fsb]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/FSB.zip FSB.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3AFGMS08,&lt;br /&gt;
  author    = {Daniel Augot and Matthieu Finiasz and Philippe Gaborit and Stéphane Manuel and Nicolas Sendrier},&lt;br /&gt;
  title     = {SHA-3 proposal: FSB},&lt;br /&gt;
  url        = {http://www-rocq.inria.fr/secret/CBCrypto/fsbdoc.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cryptoeprint:2009:292,&lt;br /&gt;
    author = {Daniel J. Bernstein and Tanja Lange and Christiane Peters and Ruben Niederhagen and Peter Schwabe},&lt;br /&gt;
    title = {Implementing Wagner's generalized birthday attack against the SHA-3 candidate FSB},&lt;br /&gt;
    howpublished = {Cryptology ePrint Archive, Report 2009/292},&lt;br /&gt;
    year = {2009},&lt;br /&gt;
    note = {\url{http://eprint.iacr.org/}},&lt;br /&gt;
    url = {http://eprint.iacr.org/2009/292.pdf},&lt;br /&gt;
    abstract = {The hash function FSB is one of the candidates submitted to NIST's competition to find the new standard hash function, SHA-3. The compression function of FSB is based on error correcting codes. In this paper we show how to use Wagner's generalized birthday attack to find collisions in FSB's compression function. In particular, we present details on our implementation attacking FSB_48, a toy version of FSB which was proposed by the FSB submitters as a training case for FSB. Our attack does not make use of any properties of the particular linear code used within FSB. FSB_48 was chosen as a target where generalized birthday attacks would be one of the strongest attacks and which could be attacked in practice.&lt;br /&gt;
&lt;br /&gt;
We show how to adapt this attack so that it runs on our computer cluster of only 10 PCs which provides far less memory than the usual implementation of generalized birthday attacks would require. This situation is very interesting for estimating the security of systems against distributed attacks using contributed off-the-shelf PCs.&lt;br /&gt;
&lt;br /&gt;
For the SHA-3 competition this result is meaningful in that it allows to assess the security of FSB against the strongest non-structural attack; it does not provide any insight in the security of this particular choice of linear code.  }&lt;br /&gt;
}&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=TIB3&amp;diff=3113</id>
		<title>TIB3</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=TIB3&amp;diff=3113"/>
		<updated>2009-05-05T07:03:37Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Tweak on TIB3&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Daniel Penazzi, Miguel Montes&lt;br /&gt;
* Website: [http://www.famaf.unc.edu.ar/~penazzi/tib3/ http://www.famaf.unc.edu.ar/~penazzi/tib3/]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/TIB3.zip TIB3.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3TIB308,&lt;br /&gt;
  author    = {Miguel Montes and Daniel Penazzi},&lt;br /&gt;
  title     = {The TIB3 Hash},&lt;br /&gt;
  url        = {http://www.famaf.unc.edu.ar/~penazzi/tib3/submitted/Supporting_Documentation/TIB3_Algorithm_Specification.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3TIB309,&lt;br /&gt;
  author    = {Miguel Montes and Daniel Penazzi},&lt;br /&gt;
  title     = {Tweak on TIB3},&lt;br /&gt;
  url        = {http://www.famaf.unc.edu.ar/~penazzi/tib3/TweakofTIB3/Supporting_Documentation/TIB3_Tweak.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|  | pseudo-collision || compression || all ||  || 2&amp;lt;sup&amp;gt;24&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/2/2b/Tib3-pseudo.pdf Mendel,Schläffer]&lt;br /&gt;
|-                    &lt;br /&gt;
|  style=&amp;quot;background:greenyellow&amp;quot; | collision || hash || 256 ||  || 2&amp;lt;sup&amp;gt;122.5&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;122.5&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/2/2b/Tib3-pseudo.pdf Mendel,Schläffer]&lt;br /&gt;
|-                    &lt;br /&gt;
|  style=&amp;quot;background:yellow&amp;quot; | collision || hash || 512 ||  || 2&amp;lt;sup&amp;gt;244.5&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;244.5&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/2/2b/Tib3-pseudo.pdf Mendel,Schläffer]&lt;br /&gt;
|-                                        &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{twisterMRS08,&lt;br /&gt;
  author    = {Florian Mendel and Martin Schläffer},&lt;br /&gt;
  title     = {On Pseudo-Collisions and Collisions for TIB3},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/2/2b/Tib3-pseudo.pdf}, &lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
  abstract = {In this paper, we present a pseudo-collision for TIB3 with a complexity of about $2^{32}$ compression function evaluations. By using message modification techniques the complexity can be further reduced. Furthermore, we show how to construct collisions for TIB3 slightly faster than brute force search using the fact that we can construct several (different) pseudo-collisions for the compression function. The complexity to construct collisions is about $2^{122.5}$ for TIB3-256 and $2^{244.5}$ for TIB3-512 with neglible memory requirements.&lt;br /&gt;
This attack shows that compression function attacks have been underestimated in the design of TIB3. Although the practicality of the proposed attacks might be debatable, it nevertheless exhibits non-random properties that are not present in the SHA-2 family and opens the possibility for further improved attacks.}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=LUX&amp;diff=3112</id>
		<title>LUX</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=LUX&amp;diff=3112"/>
		<updated>2009-05-05T07:00:50Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Specification Update of LUX&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Ivica Nikolić, Alex Biryukov, and Dmitry Khovratovich&lt;br /&gt;
* Website: [http://cryptolux.org/LUX  http://cryptolux.org/LUX]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/LUX.zip LUX.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3BiryukovKN08,&lt;br /&gt;
  author    = {Ivica Nikolić and Alex Biryukov and Dmitry Khovratovich},&lt;br /&gt;
  title     = {Hash family LUX - Algorithm Specifications and&lt;br /&gt;
Supporting Documentation},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/f/f3/LUX.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3BiryukovKN09,&lt;br /&gt;
  author    = {Ivica Nikolić and Alex Biryukov and Dmitry Khovratovich},&lt;br /&gt;
  title     = {Specification Update of the Hash Family LUX},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/c/c6/LUXadd.pdf},&lt;br /&gt;
  howpublished = {Available online (local link)},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|   Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                      &lt;br /&gt;
|  | collision || reduced hash || 224 || 3 blank rounds || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | near-collision || reduced hash || 256 || 3 blank rounds || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | free-start collision || compression || ? ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | free-start preimage || compression || ? ||  || 2&amp;lt;sup&amp;gt;80&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-   &lt;br /&gt;
|  | distinguisher || hash|| all ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu],[http://ehash.iaik.tugraz.at/uploads/7/78/Lux_nicky.txt Mouha]&lt;br /&gt;
|-                   &lt;br /&gt;
|  | distinguisher || reduced hash || 256 || 8 blank rounds || example, 2&amp;lt;sup&amp;gt;8&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/3b/LUXATTACKNext.pdf Schmidt-Nielsen],[http://ehash.iaik.tugraz.at/uploads/f/f9/LUXdistinguisher.zip Bjørstad]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | distinguisher || reduced hash || 512 || 9 blank rounds || example, 2&amp;lt;sup&amp;gt;8&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/3b/LUXATTACKNext.pdf Schmidt-Nielsen],[http://ehash.iaik.tugraz.at/uploads/f/f9/LUXdistinguisher.zip Bjørstad]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | slide-attack || hash || all || salt size: 31 mod 32 || - || - || [http://ehash.iaik.tugraz.at/uploads/6/62/Lux_peyrin.txt Peyrin]&lt;br /&gt;
|-     &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | collision|| hash || 256 || || 2&amp;lt;sup&amp;gt;100&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe],[http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt Ferguson]&lt;br /&gt;
|- &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | second preimage|| hash || 256 || || 2&amp;lt;sup&amp;gt;200&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe]&lt;br /&gt;
|- &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | collision|| hash || 512|| || 2&amp;lt;sup&amp;gt;228&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe],[http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt Ferguson]&lt;br /&gt;
|- &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | second preimage|| hash || 512|| || 2&amp;lt;sup&amp;gt;456&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe]&lt;br /&gt;
|-   &lt;br /&gt;
|  | distinguisher || HMAC, DRBG|| all ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt Ferguson]&lt;br /&gt;
|-                                &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxWFW08,&lt;br /&gt;
  author    = {Shuang Wu and Dengguo Feng and Wenling Wu},&lt;br /&gt;
  title     = {Cryptanalysis of the Hash Function LUX-256},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  abstract  = {LUX is a new hash function submitted to NIST's SHA-3 competition. In this paper, we found some non-random properties of LUX due to the weakness of origin shift vector. We also give reduced blank round collision attack, free-start collision attack and free-start preimage attack on LUX-256. The two collision attacks are trivial. The free-start preimage attack has complexity of about 2^{80} and requires negligible memory.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxS09,&lt;br /&gt;
  author    = {Peter Schmidt-Nielsen},&lt;br /&gt;
  title     = {A distinguisher for reduced-round LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/3/3b/LUXATTACKNext.pdf}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxB09,&lt;br /&gt;
  author    = {Tor E. Bjørstad},&lt;br /&gt;
  title     = {A distinguisher for reduced-round LUX (source code)},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/f/f9/LUXdistinguisher.zip},&lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxP08,&lt;br /&gt;
  author    = {Thomas Peyrin},&lt;br /&gt;
  title     = {Slide attacks on LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/6/62/Lux_peyrin.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxD09,&lt;br /&gt;
  author    = {Watanabe Dai},&lt;br /&gt;
  title     = {OFFICIAL COMMENT: LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxF09,&lt;br /&gt;
  author    = {Niels Ferguson},&lt;br /&gt;
  title     = {RE: OFFICIAL COMMENT: LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxM09,&lt;br /&gt;
  author    = {Nicky Mouha},&lt;br /&gt;
  title     = {RE: OFFICIAL COMMENT: LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/7/78/Lux_nicky.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:LUXadd.pdf&amp;diff=3111</id>
		<title>File:LUXadd.pdf</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:LUXadd.pdf&amp;diff=3111"/>
		<updated>2009-05-05T07:00:22Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3086</id>
		<title>The SHA-3 Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3086"/>
		<updated>2009-04-14T09:59:13Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The SHA-3 Zoo (work in progress) is a collection of cryptographic hash functions (in alphabetical order) submitted to the [http://www.nist.gov/hash-competition SHA-3 contest] (see also [http://en.wikipedia.org/wiki/SHA-3 here]). It aims to provide an overview of design and cryptanalysis of all submissions. A list of all [[SHA-3 submitters]] is also available. For a software performance related overview, see [http://bench.cr.yp.to/ebash.html eBASH]. At a separate page, we also collect [[SHA-3_Hardware_Implementations | hardware implementation results]] of the candidates. Another categorization of the SHA-3 submissions can be found [http://eprint.iacr.org/2008/511.pdf here].&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The idea of the SHA-3 Zoo is to give a good overview of cryptanalytic results. We try to avoid additional judgement whether a submission is broken. The answer to this question is left to NIST. However, we categorize the cryptanalytic results by their impact from very theoretic to practical attacks. A detailed description is given in [[Cryptanalysis Categories]].&lt;br /&gt;
&lt;br /&gt;
At this time, 56 out of 64 submissions to the SHA-3 competition are publicly known and available. 51 [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/submissions_rnd1.html submissions] have advanced to the first round.&lt;br /&gt;
So far, 10 out of 51 first round candidates have been officially conceded broken or withdrawn by the designers.&lt;br /&gt;
&lt;br /&gt;
The following table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are collected at the individual hash function pages. A description of the main table is given [[Cryptanalysis_Categories#Main_Cryptanalysis_Table | here]].&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/index.php?title=Special:Recentchangeslinked&amp;amp;target=The_SHA-3_Zoo&amp;amp;days=7&amp;amp;limit=50&amp;amp;hideminor=1 Recent updates of the SHA-3 Zoo]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;150&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;140&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[ARIRANG]]      || Jongin Lim || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[AURORA]]       || Masahiro Fujita  || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[BLAKE]]        || Jean-Philippe Aumasson || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Blender]]      || Colin Bradbury || style=&amp;quot;background:orange&amp;quot; | collision, preimage || near-collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Blue Midnight Wish]] || Svein Johan Knapskog || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Cheetah]]      || Dmitry Khovratovich || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CHI]]          || Phillip Hawkes || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[CRUNCH]]       || Jacques Patarin || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CubeHash]]     || Daniel J. Bernstein || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA]]  || Xu Zijie || style=&amp;quot;background:orange&amp;quot;|collision || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA2]] || Xu Zijie || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[ECHO]]         || Henri Gilbert || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ECOH]]         || Daniel R. L. Brown || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R (SHA-3 submission)|Edon-R]] || Danilo Gligoroski || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[EnRUPT]]       || Sean O'Neil || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ESSENCE]]      || Jason Worth Martin || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB (SHA-3 submission) | FSB]] || Matthieu Finiasz || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Fugue]]        || Charanjit S. Jutla || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Groestl|Grøstl]] || Lars R. Knudsen || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Hamsi]]        || &amp;lt;nowiki&amp;gt;Özgül Kü&amp;amp;#231;ük&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[JH]]           || Hongjun Wu || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Keccak]]       || The Keccak Team || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LANE]]         || Sebastiaan Indesteege || ||&lt;br /&gt;
|-                         &lt;br /&gt;
| [[Lesamnta]]     || Hirotaka Yoshida || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Luffa]]        || Dai Watanabe || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LUX]]          || &amp;lt;nowiki&amp;gt;Ivica Nikoli&amp;amp;#263;&amp;lt;/nowiki&amp;gt; || style=&amp;quot;background:orange&amp;quot; | collision, 2nd preimage || DRBG,HMAC&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[MCSSHA-3]]     || Mikhail Maslennikov || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[MD6]]          || Ronald L. Rivest || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[NaSHA]]        || Smile Markovski || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SANDstorm]]    || Rich Schroeppel || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Sarmal]]       || &amp;lt;nowiki&amp;gt;Kerem Var&amp;amp;#305;c&amp;amp;#305;&amp;lt;/nowiki&amp;gt; ||  style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Sgàil]]        || Peter Maxwell|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Shabal]]       || &amp;lt;nowiki&amp;gt;Jean-Fran&amp;amp;#231;ois Misarsky&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAvite-3]]    || Orr Dunkelman || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SIMD]]         || &amp;lt;nowiki&amp;gt;Ga&amp;amp;#235;tan Leurent&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Skein]]        || Bruce Schneier || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Spectral Hash]] || &amp;lt;nowiki&amp;gt;&amp;amp;#199;etin Kaya Ko&amp;amp;#231;&amp;lt;/nowiki&amp;gt; || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFTX]]      || Daniele Micciancio || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[TIB3]]         || Daniel Penazzi || style=&amp;quot;background:yellow&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Twister]]      || Michael Gorski || style=&amp;quot;background:orange&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Vortex (SHA-3 submission)|Vortex]] || Michael Kounavis || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following hash functions have been submitted to the NIST competition but did not advance to the first round, or have been conceded broken or withdrawn by the designers:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot; | Status !! width=&amp;quot;120&amp;quot; | Best Attack on Main NIST Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Abacus]]      || Neil Sholer || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Boole]]       || Greg Rose || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[DCH]]         || David A. Wilson || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[HASH 2X]]     || Jason Lee || not in round 1 || style=&amp;quot;background:red&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Khichidi-1]]  || M. Vidyasagar || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Maraca]]      || Robert J. Jenkins || not in round 1 || style=&amp;quot;background:red&amp;quot; | preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[MeshHash]]    || Björn Fay || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[NKS2D]]       || Geoffrey Park || not in round 1 || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Ponic]]       || Peter Schmidt-Nielsen || not in round 1 || style=&amp;quot;background:yellow&amp;quot; | 2nd-preimage&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[SHAMATA]]      || Orhun Kara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                         &lt;br /&gt;
| [[StreamHash]]   || Michal Trojnara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Tangle]]      || Rafael Alvarez || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[WaMM]]        || John Washburn || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Waterfall]]   || Bob Hattersley || conceded broken || style=&amp;quot;background:orange&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[ZK-Crypt]]       || Carmi Gressel || not in round 1 ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your analysis is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3085</id>
		<title>The SHA-3 Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3085"/>
		<updated>2009-04-14T09:57:32Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The SHA-3 Zoo (work in progress) is a collection of cryptographic hash functions (in alphabetical order) submitted to the [http://www.nist.gov/hash-competition SHA-3 contest] (see also [http://en.wikipedia.org/wiki/SHA-3 here]). It aims to provide an overview of design and cryptanalysis of all submissions. A list of all [[SHA-3 submitters]] is also available. For a software performance related overview, see [http://bench.cr.yp.to/ebash.html eBASH]. At a separate page, we also collect [[SHA-3_Hardware_Implementations | hardware implementation results]] of the candidates. Another categorization of the SHA-3 submissions can be found [http://eprint.iacr.org/2008/511.pdf here].&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The idea of the SHA-3 Zoo is to give a good overview of cryptanalytic results. We try to avoid additional judgement whether a submission is broken. The answer to this question is left to NIST. However, we categorize the cryptanalytic results by their impact from very theoretic to practical attacks. A detailed description is given in [[Cryptanalysis Categories]].&lt;br /&gt;
&lt;br /&gt;
At this time, 56 out of 64 submissions to the SHA-3 competition are publicly known and available. 51 [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/submissions_rnd1.html submissions] have advanced to the first round.&lt;br /&gt;
So far, 10 out of 51 first round candidates have been officially conceded broken or withdrawn by the designers.&lt;br /&gt;
&lt;br /&gt;
The following table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are collected at the individual hash function pages. A description of the main table is given [[Cryptanalysis_Categories#Main_Cryptanalysis_Table | here]].&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/index.php?title=Special:Recentchangeslinked&amp;amp;target=The_SHA-3_Zoo&amp;amp;days=7&amp;amp;limit=50&amp;amp;hideminor=1 Recent updates of the SHA-3 Zoo]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;160&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[ARIRANG]]      || Jongin Lim || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[AURORA]]       || Masahiro Fujita  || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[BLAKE]]        || Jean-Philippe Aumasson || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Blender]]      || Colin Bradbury || style=&amp;quot;background:orange&amp;quot; | collision, preimage || near-collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Blue Midnight Wish]] || Svein Johan Knapskog || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Cheetah]]      || Dmitry Khovratovich || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CHI]]          || Phillip Hawkes || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[CRUNCH]]       || Jacques Patarin || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CubeHash]]     || Daniel J. Bernstein || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA]]  || Xu Zijie || style=&amp;quot;background:orange&amp;quot;|collision || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA2]] || Xu Zijie || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[ECHO]]         || Henri Gilbert || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ECOH]]         || Daniel R. L. Brown || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R (SHA-3 submission)|Edon-R]] || Danilo Gligoroski || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[EnRUPT]]       || Sean O'Neil || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ESSENCE]]      || Jason Worth Martin || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB (SHA-3 submission) | FSB]] || Matthieu Finiasz || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Fugue]]        || Charanjit S. Jutla || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Groestl|Grøstl]] || Lars R. Knudsen || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Hamsi]]        || &amp;lt;nowiki&amp;gt;Özgül Kü&amp;amp;#231;ük&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[JH]]           || Hongjun Wu || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Keccak]]       || The Keccak Team || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LANE]]         || Sebastiaan Indesteege || ||&lt;br /&gt;
|-                         &lt;br /&gt;
| [[Lesamnta]]     || Hirotaka Yoshida || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Luffa]]        || Dai Watanabe || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LUX]]          || &amp;lt;nowiki&amp;gt;Ivica Nikoli&amp;amp;#263;&amp;lt;/nowiki&amp;gt; || style=&amp;quot;background:orange&amp;quot; | collision, 2nd preimage || DRBG,HMAC&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[MCSSHA-3]]     || Mikhail Maslennikov || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[MD6]]          || Ronald L. Rivest || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[NaSHA]]        || Smile Markovski || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SANDstorm]]    || Rich Schroeppel || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Sarmal]]       || &amp;lt;nowiki&amp;gt;Kerem Var&amp;amp;#305;c&amp;amp;#305;&amp;lt;/nowiki&amp;gt; ||  style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Sgàil]]        || Peter Maxwell|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Shabal]]       || &amp;lt;nowiki&amp;gt;Jean-Fran&amp;amp;#231;ois Misarsky&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAvite-3]]    || Orr Dunkelman || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SIMD]]         || &amp;lt;nowiki&amp;gt;Ga&amp;amp;#235;tan Leurent&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Skein]]        || Bruce Schneier || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Spectral Hash]] || &amp;lt;nowiki&amp;gt;&amp;amp;#199;etin Kaya Ko&amp;amp;#231;&amp;lt;/nowiki&amp;gt; || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFTX]]      || Daniele Micciancio || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[TIB3]]         || Daniel Penazzi || style=&amp;quot;background:yellow&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Twister]]      || Michael Gorski || style=&amp;quot;background:orange&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Vortex (SHA-3 submission)|Vortex]] || Michael Kounavis || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following hash functions have been submitted to the NIST competition but did not advance to the first round, or have been conceded broken or withdrawn by the designers:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot; | Status !! width=&amp;quot;120&amp;quot; | Best Attack on Main NIST Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Abacus]]      || Neil Sholer || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Boole]]       || Greg Rose || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[DCH]]         || David A. Wilson || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[HASH 2X]]     || Jason Lee || not in round 1 || style=&amp;quot;background:red&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Khichidi-1]]  || M. Vidyasagar || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Maraca]]      || Robert J. Jenkins || not in round 1 || style=&amp;quot;background:red&amp;quot; | preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[MeshHash]]    || Björn Fay || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[NKS2D]]       || Geoffrey Park || not in round 1 || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Ponic]]       || Peter Schmidt-Nielsen || not in round 1 || style=&amp;quot;background:yellow&amp;quot; | 2nd-preimage&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[SHAMATA]]      || Orhun Kara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                         &lt;br /&gt;
| [[StreamHash]]   || Michal Trojnara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Tangle]]      || Rafael Alvarez || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[WaMM]]        || John Washburn || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Waterfall]]   || Bob Hattersley || conceded broken || style=&amp;quot;background:orange&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[ZK-Crypt]]       || Carmi Gressel || not in round 1 ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your analysis is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3084</id>
		<title>The SHA-3 Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3084"/>
		<updated>2009-04-14T09:56:00Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: collision, 2nd-preimage and other attacks on LUX&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The SHA-3 Zoo (work in progress) is a collection of cryptographic hash functions (in alphabetical order) submitted to the [http://www.nist.gov/hash-competition SHA-3 contest] (see also [http://en.wikipedia.org/wiki/SHA-3 here]). It aims to provide an overview of design and cryptanalysis of all submissions. A list of all [[SHA-3 submitters]] is also available. For a software performance related overview, see [http://bench.cr.yp.to/ebash.html eBASH]. At a separate page, we also collect [[SHA-3_Hardware_Implementations | hardware implementation results]] of the candidates. Another categorization of the SHA-3 submissions can be found [http://eprint.iacr.org/2008/511.pdf here].&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The idea of the SHA-3 Zoo is to give a good overview of cryptanalytic results. We try to avoid additional judgement whether a submission is broken. The answer to this question is left to NIST. However, we categorize the cryptanalytic results by their impact from very theoretic to practical attacks. A detailed description is given in [[Cryptanalysis Categories]].&lt;br /&gt;
&lt;br /&gt;
At this time, 56 out of 64 submissions to the SHA-3 competition are publicly known and available. 51 [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/submissions_rnd1.html submissions] have advanced to the first round.&lt;br /&gt;
So far, 10 out of 51 first round candidates have been officially conceded broken or withdrawn by the designers.&lt;br /&gt;
&lt;br /&gt;
The following table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are collected at the individual hash function pages. A description of the main table is given [[Cryptanalysis_Categories#Main_Cryptanalysis_Table | here]].&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/index.php?title=Special:Recentchangeslinked&amp;amp;target=The_SHA-3_Zoo&amp;amp;days=7&amp;amp;limit=50&amp;amp;hideminor=1 Recent updates of the SHA-3 Zoo]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;140&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[ARIRANG]]      || Jongin Lim || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[AURORA]]       || Masahiro Fujita  || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[BLAKE]]        || Jean-Philippe Aumasson || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Blender]]      || Colin Bradbury || style=&amp;quot;background:orange&amp;quot; | collision, preimage || near-collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Blue Midnight Wish]] || Svein Johan Knapskog || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Cheetah]]      || Dmitry Khovratovich || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CHI]]          || Phillip Hawkes || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[CRUNCH]]       || Jacques Patarin || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CubeHash]]     || Daniel J. Bernstein || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA]]  || Xu Zijie || style=&amp;quot;background:orange&amp;quot;|collision || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA2]] || Xu Zijie || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[ECHO]]         || Henri Gilbert || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ECOH]]         || Daniel R. L. Brown || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R (SHA-3 submission)|Edon-R]] || Danilo Gligoroski || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[EnRUPT]]       || Sean O'Neil || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ESSENCE]]      || Jason Worth Martin || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB (SHA-3 submission) | FSB]] || Matthieu Finiasz || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Fugue]]        || Charanjit S. Jutla || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Groestl|Grøstl]] || Lars R. Knudsen || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Hamsi]]        || &amp;lt;nowiki&amp;gt;Özgül Kü&amp;amp;#231;ük&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[JH]]           || Hongjun Wu || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Keccak]]       || The Keccak Team || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LANE]]         || Sebastiaan Indesteege || ||&lt;br /&gt;
|-                         &lt;br /&gt;
| [[Lesamnta]]     || Hirotaka Yoshida || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Luffa]]        || Dai Watanabe || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LUX]]          || &amp;lt;nowiki&amp;gt;Ivica Nikoli&amp;amp;#263;&amp;lt;/nowiki&amp;gt; || style=&amp;quot;background:orange&amp;quot; | collision, 2nd preimage || DRBG,HMAC&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[MCSSHA-3]]     || Mikhail Maslennikov || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[MD6]]          || Ronald L. Rivest || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[NaSHA]]        || Smile Markovski || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SANDstorm]]    || Rich Schroeppel || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Sarmal]]       || &amp;lt;nowiki&amp;gt;Kerem Var&amp;amp;#305;c&amp;amp;#305;&amp;lt;/nowiki&amp;gt; ||  style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Sgàil]]        || Peter Maxwell|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Shabal]]       || &amp;lt;nowiki&amp;gt;Jean-Fran&amp;amp;#231;ois Misarsky&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAvite-3]]    || Orr Dunkelman || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SIMD]]         || &amp;lt;nowiki&amp;gt;Ga&amp;amp;#235;tan Leurent&amp;lt;/nowiki&amp;gt; || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Skein]]        || Bruce Schneier || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Spectral Hash]] || &amp;lt;nowiki&amp;gt;&amp;amp;#199;etin Kaya Ko&amp;amp;#231;&amp;lt;/nowiki&amp;gt; || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFTX]]      || Daniele Micciancio || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[TIB3]]         || Daniel Penazzi || style=&amp;quot;background:yellow&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Twister]]      || Michael Gorski || style=&amp;quot;background:orange&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Vortex (SHA-3 submission)|Vortex]] || Michael Kounavis || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following hash functions have been submitted to the NIST competition but did not advance to the first round, or have been conceded broken or withdrawn by the designers:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot; | Status !! width=&amp;quot;120&amp;quot; | Best Attack on Main NIST Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Abacus]]      || Neil Sholer || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Boole]]       || Greg Rose || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[DCH]]         || David A. Wilson || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[HASH 2X]]     || Jason Lee || not in round 1 || style=&amp;quot;background:red&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Khichidi-1]]  || M. Vidyasagar || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Maraca]]      || Robert J. Jenkins || not in round 1 || style=&amp;quot;background:red&amp;quot; | preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[MeshHash]]    || Björn Fay || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[NKS2D]]       || Geoffrey Park || not in round 1 || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Ponic]]       || Peter Schmidt-Nielsen || not in round 1 || style=&amp;quot;background:yellow&amp;quot; | 2nd-preimage&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[SHAMATA]]      || Orhun Kara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                         &lt;br /&gt;
| [[StreamHash]]   || Michal Trojnara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Tangle]]      || Rafael Alvarez || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[WaMM]]        || John Washburn || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Waterfall]]   || Bob Hattersley || conceded broken || style=&amp;quot;background:orange&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[ZK-Crypt]]       || Carmi Gressel || not in round 1 ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your analysis is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=LUX&amp;diff=3083</id>
		<title>LUX</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=LUX&amp;diff=3083"/>
		<updated>2009-04-14T09:47:34Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: collision, 2nd-preimage, and other attacks on LUX&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Ivica Nikolić, Alex Biryukov, and Dmitry Khovratovich&lt;br /&gt;
* Website: [http://cryptolux.org/LUX  http://cryptolux.org/LUX]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/LUX.zip LUX.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3BiryukovKN,&lt;br /&gt;
  author    = {Ivica Nikolić and Alex Biryukov and Dmitry Khovratovich},&lt;br /&gt;
  title     = {Hash family LUX - Algorithm Specifications and&lt;br /&gt;
Supporting Documentation},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/f/f3/LUX.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|   Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                      &lt;br /&gt;
|  | collision || reduced hash || 224 || 3 blank rounds || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | near-collision || reduced hash || 256 || 3 blank rounds || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | free-start collision || compression || ? ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | free-start preimage || compression || ? ||  || 2&amp;lt;sup&amp;gt;80&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-   &lt;br /&gt;
|  | distinguisher || hash|| 256/512 ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu],[http://ehash.iaik.tugraz.at/uploads/7/78/Lux_nicky.txt Mouha]&lt;br /&gt;
|-                   &lt;br /&gt;
|  | distinguisher || reduced hash || 256 || 8 blank rounds || example, 2&amp;lt;sup&amp;gt;8&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/3b/LUXATTACKNext.pdf Schmidt-Nielsen],[http://ehash.iaik.tugraz.at/uploads/f/f9/LUXdistinguisher.zip Bjørstad]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | distinguisher || reduced hash || 512 || 9 blank rounds || example, 2&amp;lt;sup&amp;gt;8&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/3b/LUXATTACKNext.pdf Schmidt-Nielsen],[http://ehash.iaik.tugraz.at/uploads/f/f9/LUXdistinguisher.zip Bjørstad]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | slide-attack || hash || all || salt size: 31 mod 32 || - || - || [http://ehash.iaik.tugraz.at/uploads/6/62/Lux_peyrin.txt Peyrin]&lt;br /&gt;
|-     &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | collision|| hash || 256 || || 2&amp;lt;sup&amp;gt;100&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe],[http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt Ferguson]&lt;br /&gt;
|- &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | second preimage|| hash || 256 || || 2&amp;lt;sup&amp;gt;200&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe]&lt;br /&gt;
|- &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | collision|| hash || 512|| || 2&amp;lt;sup&amp;gt;228&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe],[http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt Ferguson]&lt;br /&gt;
|- &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot;  | second preimage|| hash || 512|| || 2&amp;lt;sup&amp;gt;456&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt Watanabe]&lt;br /&gt;
|-   &lt;br /&gt;
|  | distinguisher || HMAC, DRBG|| all ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt Ferguson]&lt;br /&gt;
|-                                &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxWFW08,&lt;br /&gt;
  author    = {Shuang Wu and Dengguo Feng and Wenling Wu},&lt;br /&gt;
  title     = {Cryptanalysis of the Hash Function LUX-256},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  abstract  = {LUX is a new hash function submitted to NIST's SHA-3 competition. In this paper, we found some non-random properties of LUX due to the weakness of origin shift vector. We also give reduced blank round collision attack, free-start collision attack and free-start preimage attack on LUX-256. The two collision attacks are trivial. The free-start preimage attack has complexity of about 2^{80} and requires negligible memory.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxS09,&lt;br /&gt;
  author    = {Peter Schmidt-Nielsen},&lt;br /&gt;
  title     = {A distinguisher for reduced-round LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/3/3b/LUXATTACKNext.pdf}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxB09,&lt;br /&gt;
  author    = {Tor E. Bjørstad},&lt;br /&gt;
  title     = {A distinguisher for reduced-round LUX (source code)},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/f/f9/LUXdistinguisher.zip},&lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxP08,&lt;br /&gt;
  author    = {Thomas Peyrin},&lt;br /&gt;
  title     = {Slide attacks on LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/6/62/Lux_peyrin.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxD09,&lt;br /&gt;
  author    = {Watanabe Dai},&lt;br /&gt;
  title     = {OFFICIAL COMMENT: LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/e/ec/Lux_dai.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxF09,&lt;br /&gt;
  author    = {Niels Ferguson},&lt;br /&gt;
  title     = {RE: OFFICIAL COMMENT: LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/2/21/Lux_niels.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxM09,&lt;br /&gt;
  author    = {Nicky Mouha},&lt;br /&gt;
  title     = {RE: OFFICIAL COMMENT: LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/7/78/Lux_nicky.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Lux_nicky.txt&amp;diff=3082</id>
		<title>File:Lux nicky.txt</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Lux_nicky.txt&amp;diff=3082"/>
		<updated>2009-04-14T09:37:54Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Lux_niels.txt&amp;diff=3081</id>
		<title>File:Lux niels.txt</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Lux_niels.txt&amp;diff=3081"/>
		<updated>2009-04-14T09:32:46Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Lux_dai.txt&amp;diff=3080</id>
		<title>File:Lux dai.txt</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Lux_dai.txt&amp;diff=3080"/>
		<updated>2009-04-14T09:13:46Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Shabal&amp;diff=3069</id>
		<title>Shabal</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Shabal&amp;diff=3069"/>
		<updated>2009-04-09T09:29:41Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: new nonrandomness observations on the Shabal permutation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Emmanuel Bresson, Anne Canteaut, Benoît Chevallier-Mames, Christophe Clavier, Thomas Fuhr, Aline Gouget, Thomas Icart, Jean-François Misarsky, Marìa Naya-Plasencia, Pascal Paillier, Thomas Pornin, Jean-René Reinhard, Céline Thuillet, Marion Videau&lt;br /&gt;
* Website: http://www.shabal.com/&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Shabal.zip Shabal.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3CanteautCGPP08,&lt;br /&gt;
  author    = {Emmanuel Bresson and Anne Canteaut and Benoît Chevallier-Mames and Christophe Clavier and Thomas Fuhr and Aline Gouget and Thomas Icart and Jean-François Misarsky and Marìa Naya-Plasencia and Pascal Paillier and Thomas Pornin and Jean-René Reinhard and Céline Thuillet and Marion Videau},&lt;br /&gt;
  title     = {Shabal, a Submission to NIST’s Cryptographic Hash Algorithm Competition},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/6/6c/Shabal.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|   Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|   | non-randomness || permutation || all ||  || 2&amp;lt;sup&amp;gt;12&amp;lt;/sup&amp;gt; ||  || [http://131002.net/data/papers/Aum09.pdf Aumasson]&lt;br /&gt;
|-                                              &lt;br /&gt;
|   | non-randomness || permutation || all ||  || 1 ||  || [http://www.mat.dtu.dk/people/S.Thomsen/shabal/shabal.pdf Knudsen, Matusiewicz, Thomsen]&lt;br /&gt;
|-                                              &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalAum09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson},&lt;br /&gt;
  title     = {On the pseudorandomness of Shabal's keyed permutation},&lt;br /&gt;
  url        = {http://131002.net/data/papers/Aum09.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  abstract = {&lt;br /&gt;
  We report observations suggesting that the permutation used in&lt;br /&gt;
  Shabal does not behave pseudorandomly. This does not affect the&lt;br /&gt;
  security of Shabal as submitted to the NIST Hash Competition.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{shabalKMT09,&lt;br /&gt;
  author    = {Lars R. Knudsen and Krystian Matusiewicz and Søren S. Thomsen},&lt;br /&gt;
  title     = {Observations on the Shabal keyed permutation},&lt;br /&gt;
  url        = {http://www.mat.dtu.dk/people/S.Thomsen/shabal/shabal.pdf },&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  abstract = {&lt;br /&gt;
 In this note we show that the permutation P used in the Shabal hash function, which is&lt;br /&gt;
a candidate in the SHA-3 competition, has some non-random properties. As an example,&lt;br /&gt;
it is easy to find a number of fixed points in the permutation. Moreover, large key-multicollisions&lt;br /&gt;
can be easily found; these are multi-collisions where only the key input contains&lt;br /&gt;
a difference. All observations are easily verified, and most of them are independent of the&lt;br /&gt;
choice of security parameters. Our observations, on the other hand, do not seem extensible&lt;br /&gt;
to the full hash function.&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3052</id>
		<title>The SHA-3 Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3052"/>
		<updated>2009-04-01T07:08:16Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: near-collision resistance is a NIST requirement, added practical attack on Blender&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The SHA-3 Zoo (work in progress) is a collection of cryptographic hash functions (in alphabetical order) submitted to the [http://www.nist.gov/hash-competition SHA-3 contest] (see also [http://en.wikipedia.org/wiki/SHA-3 here]). It aims to provide an overview of design and cryptanalysis of all submissions. A list of all [[SHA-3 submitters]] is also available. For a software performance related overview, see [http://bench.cr.yp.to/ebash.html eBASH]. At a separate page, we also collect [[SHA-3_Hardware_Implementations | hardware implementation results]] of the candidates. Another categorization of the SHA-3 submissions can be found [http://eprint.iacr.org/2008/511.pdf here].&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The idea of the SHA-3 Zoo is to give a good overview of cryptanalytic results. We try to avoid additional judgement whether a submission is broken. The answer to this question is left to NIST. However, we categorize the cryptanalytic results by their impact from very theoretic to practical attacks. A detailed description is given in [[Cryptanalysis Categories]].&lt;br /&gt;
&lt;br /&gt;
At this time, 56 out of 64 submissions to the SHA-3 competition are publicly known and available. 51 [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/submissions_rnd1.html submissions] have advanced to the first round.&lt;br /&gt;
So far, 10 out of 51 first round candidates have been officially conceded broken or withdrawn by the designers.&lt;br /&gt;
&lt;br /&gt;
The following table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are collected at the individual hash function pages. A description of the main table is given [[Cryptanalysis_Categories#Main_Cryptanalysis_Table | here]].&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/index.php?title=Special:Recentchangeslinked&amp;amp;target=The_SHA-3_Zoo&amp;amp;days=7&amp;amp;limit=50&amp;amp;hideminor=1 Recent updates of the SHA-3 Zoo]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;140&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[ARIRANG]]      || Jongin Lim || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[AURORA]]       || Masahiro Fujita  || style=&amp;quot;background:orange&amp;quot;| 2nd preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[BLAKE]]        || Jean-Philippe Aumasson || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Blender]]      || Colin Bradbury || style=&amp;quot;background:orange&amp;quot; | preimage || near-collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Blue Midnight Wish]] || Svein Johan Knapskog || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Cheetah]]      || Dmitry Khovratovich || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CHI]]          || Phillip Hawkes || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[CRUNCH]]       || Jacques Patarin || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CubeHash]]     || Daniel J. Bernstein || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA]]  || Xu Zijie || style=&amp;quot;background:orange&amp;quot;|collision || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA2]] || Xu Zijie || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[ECHO]]         || Henri Gilbert || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ECOH]]         || Daniel R. L. Brown || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R (SHA-3 submission)|Edon-R]] || Danilo Gligoroski || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[EnRUPT]]       || Sean O’Neil || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ESSENCE]]      || Jason Worth Martin || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB (SHA-3 submission) | FSB]] || Matthieu Finiasz || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Fugue]]        || Charanjit S. Jutla || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Groestl|Grøstl]] || Lars R. Knudsen || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Hamsi]]        || Ozgul Kucuk || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[JH]]           || Hongjun Wu || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Keccak]]       || The Keccak Team || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LANE]]         || Sebastiaan Indesteege || ||&lt;br /&gt;
|-                         &lt;br /&gt;
| [[Lesamnta]]     || Hirotaka Yoshida || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Luffa]]        || Dai Watanabe || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LUX]]          || Ivica Nikolic || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[MCSSHA-3]]     || Mikhail Maslennikov || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[MD6]]          || Ronald L. Rivest || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[NaSHA]]        || Smile Markovski || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SANDstorm]]    || Rich Schroeppel || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Sarmal]]       || Kerem Varici ||  style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Sgàil]]        || Peter Maxwell|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Shabal]]       || Jean-Francois Misarsky || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAvite-3]]    || Orr Dunkelman || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SIMD]]         || Gaetan Leurent || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Skein]]        || Bruce Schneier || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Spectral Hash]] || Cetin Kaya Koc || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFTX]]      || Daniele Micciancio || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[TIB3]]         || Daniel Penazzi || style=&amp;quot;background:yellow&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Twister]]      || Michael Gorski || style=&amp;quot;background:orange&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Vortex (SHA-3 submission)|Vortex]] || Michael Kounavis || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following hash functions have been submitted to the NIST competition but did not advance to the first round, or have been conceded broken or withdrawn by the designers:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot; | Status !! width=&amp;quot;120&amp;quot; | Best Attack on Main NIST Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Abacus]]      || Neil Sholer || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Boole]]       || Greg Rose || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[DCH]]         || David A. Wilson || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[HASH 2X]]     || Jason Lee || not in round 1 || style=&amp;quot;background:red&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Khichidi-1]]  || M. Vidyasagar || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Maraca]]      || Robert J. Jenkins || not in round 1 || style=&amp;quot;background:red&amp;quot; | preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[MeshHash]]    || Björn Fay || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[NKS2D]]       || Geoffrey Park || not in round 1 || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Ponic]]       || Peter Schmidt-Nielsen || not in round 1 || style=&amp;quot;background:yellow&amp;quot; | 2nd-preimage&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[SHAMATA]]      || Orhun Kara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                         &lt;br /&gt;
| [[StreamHash]]   || Michal Trojnara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Tangle]]      || Rafael Alvarez || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[WaMM]]        || John Washburn || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Waterfall]]   || Bob Hattersley || conceded broken || style=&amp;quot;background:orange&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[ZK-Crypt]]       || Carmi Gressel || not in round 1 ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your analysis is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=ARIRANG&amp;diff=3050</id>
		<title>ARIRANG</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=ARIRANG&amp;diff=3050"/>
		<updated>2009-03-31T14:41:48Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Donghoon Chang, Seokhie Hong, Changheon Kang, Jinkeon Kang, Jongsung Kim, Changhoon Lee, Jesang Lee, Jongtae Lee, Sangjin Lee, Yuseop Lee, Jongin Lim, Jaechul Sung&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* Website:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/ARIRANG.zip ARIRANG.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3ChangHKK+08,&lt;br /&gt;
  author    = {Donghoon Chang and Seokhie Hong and Changheon Kang and Jinkeon Kang and Jongsung Kim and Changhoon Lee and Jesang Lee and Jongtae Lee and Sangjin Lee and Yuseop Lee and Jongin Lim and Jaechul Sung},&lt;br /&gt;
  title     = {ARIRANG},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/2/2c/Arirang.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|   | collision|| reduced compression || 256/512 || 26 steps || example, 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | near-collision|| compression || 256/512  || full || example, 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | pseudo-collision|| hash|| 224|| full || example, 2&amp;lt;sup&amp;gt;23&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | pseudo-collision|| hash|| 384|| full || example, 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
                          &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{ArirangGMKLW09,&lt;br /&gt;
 author = {Jian Guo, Krystian Matusiewicz, Lars R. Knudsen, San Ling, and&lt;br /&gt;
Huaxiong Wang},&lt;br /&gt;
 title = {Practical pseudo-collisions for hash functions&lt;br /&gt;
ARIRANG-224/384},&lt;br /&gt;
 url = {http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf },&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=ARIRANG&amp;diff=3046</id>
		<title>ARIRANG</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=ARIRANG&amp;diff=3046"/>
		<updated>2009-03-30T13:29:20Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Donghoon Chang, Seokhie Hong, Changheon Kang, Jinkeon Kang, Jongsung Kim, Changhoon Lee, Jesang Lee, Jongtae Lee, Sangjin Lee, Yuseop Lee, Jongin Lim, Jaechul Sung&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* Website:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/ARIRANG.zip ARIRANG.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3ChangHKK+08,&lt;br /&gt;
  author    = {Donghoon Chang and Seokhie Hong and Changheon Kang and Jinkeon Kang and Jongsung Kim and Changhoon Lee and Jesang Lee and Jongtae Lee and Sangjin Lee and Yuseop Lee and Jongin Lim and Jaechul Sung},&lt;br /&gt;
  title     = {ARIRANG},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/2/2c/Arirang.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|   | collision|| reduced compression || 256/512 || 26 steps || example, 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | near-collision|| compression || 256/512  || full || example, 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | pseudo-collision|| hash|| 224|| full || example, 2&amp;lt;sup&amp;gt;23&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | pseudo-collision|| hash|| 384|| full || example, 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
                          &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{ArirangGMKLW09,&lt;br /&gt;
 author = {Jian Guo, Krystian Matusiewicz, Lars R. Knudsen, San Ling, and&lt;br /&gt;
Huaxiong Wan},&lt;br /&gt;
 title = {Practical pseudo-collisions for hash functions&lt;br /&gt;
ARIRANG-224/384},&lt;br /&gt;
 url = {http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf },&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=ARIRANG&amp;diff=3045</id>
		<title>ARIRANG</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=ARIRANG&amp;diff=3045"/>
		<updated>2009-03-30T13:24:15Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Practical compression function attacks on Arirang&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Donghoon Chang, Seokhie Hong, Changheon Kang, Jinkeon Kang, Jongsung Kim, Changhoon Lee, Jesang Lee, Jongtae Lee, Sangjin Lee, Yuseop Lee, Jongin Lim, Jaechul Sung&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* Website:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/ARIRANG.zip ARIRANG.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3ChangHKK+08,&lt;br /&gt;
  author    = {Donghoon Chang and Seokhie Hong and Changheon Kang and Jinkeon Kang and Jongsung Kim and Changhoon Lee and Jesang Lee and Jongtae Lee and Sangjin Lee and Yuseop Lee and Jongin Lim and Jaechul Sung},&lt;br /&gt;
  title     = {ARIRANG},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/2/2c/Arirang.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|   | collision|| reduced compression || 256/512 || 26 steps || 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | near-collision|| compression || 256/512  || full || 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | pseudo-collision|| hash|| 224|| full || 2&amp;lt;sup&amp;gt;23&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
|   | pseudo-collision|| hash|| 384|| full || 1 || - || [http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf Guo, Matusiewicz, Knudsen, Ling, Wang]&lt;br /&gt;
|-                  &lt;br /&gt;
                          &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{ArirangGMKLW09,&lt;br /&gt;
 author = {Jian Guo, Krystian Matusiewicz, Lars R. Knudsen, San Ling, and&lt;br /&gt;
Huaxiong Wan},&lt;br /&gt;
 title = {Practical pseudo-collisions for hash functions&lt;br /&gt;
ARIRANG-224/384},&lt;br /&gt;
 url = {http://ehash.iaik.tugraz.at/uploads/9/9a/Arirang-pseudo-sha3zoo.pdf },&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Arirang-pseudo-sha3zoo.pdf&amp;diff=3044</id>
		<title>File:Arirang-pseudo-sha3zoo.pdf</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Arirang-pseudo-sha3zoo.pdf&amp;diff=3044"/>
		<updated>2009-03-30T12:57:34Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Vortex_(SHA-3_submission)&amp;diff=3030</id>
		<title>Vortex (SHA-3 submission)</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Vortex_(SHA-3_submission)&amp;diff=3030"/>
		<updated>2009-03-24T10:22:47Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: color of collision attacks to green&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Michael Kounavis, Shay Gueron&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* Website: &lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Vortex.zip Vortex.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3KounavisG08,&lt;br /&gt;
  author    = {Michael Kounavis and Shay Gueron},&lt;br /&gt;
  title     = {Vortex: A New Family of One Way Hash Functions based on Rijndael Rounds and Carry-less Multiplication},&lt;br /&gt;
  url        = {http://eprint.iacr.org/2008/464.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|  Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference                    &lt;br /&gt;
|-                              &lt;br /&gt;
|   | correlation analysis || hash || all ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/6/6d/Vortex_correlation.txt Ferguson]&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:yellow&amp;quot;| preimage || hash || 256 ||  || 2&amp;lt;sup&amp;gt;195&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;64&amp;lt;/sup&amp;gt; || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:yellow&amp;quot;| preimage || hash || 512 ||  || 2&amp;lt;sup&amp;gt;387&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;128&amp;lt;/sup&amp;gt; || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-&lt;br /&gt;
|   style=&amp;quot;background:greenyellow&amp;quot;| collision || hash || 256 ||  || 2&amp;lt;sup&amp;gt;124.5&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;124.5&amp;lt;/sup&amp;gt; || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-  &lt;br /&gt;
|   style=&amp;quot;background:greenyellow&amp;quot;| collision || hash || 512 ||  || 2&amp;lt;sup&amp;gt;251.7&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;251.7&amp;lt;/sup&amp;gt; || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-  &lt;br /&gt;
|   | distinguisher || hash || 256 ||  || 2&amp;lt;sup&amp;gt;97&amp;lt;/sup&amp;gt; || - || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-       &lt;br /&gt;
|   | 2nd preimage || hash || 256 || weak messages || 2&amp;lt;sup&amp;gt;129&amp;lt;/sup&amp;gt; || - || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-  &lt;br /&gt;
|   | 2nd preimage || hash || 256 || weak messages || 2&amp;lt;sup&amp;gt;33&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;135&amp;lt;/sup&amp;gt; || [http://www.131002.net/data/papers/ADMRT09.pdf Aumasson,Dunkelman,Mendel,Rechberger,Thomsen]&lt;br /&gt;
|-        &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{VortexF08,&lt;br /&gt;
  author    = {Niels Ferguson},&lt;br /&gt;
  title     = {Simple correlation on some of the output bits of Vortex},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/6/6d/Vortex_correlation.txt},&lt;br /&gt;
  howpublished = {OFFICIAL COMMENT (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@inproceedings{ADMRT09,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Orr Dunkelman and Florian Mendel and Christian Rechberger and Søren S. Thomsen},&lt;br /&gt;
  title     = {Cryptanalysis of Vortex},&lt;br /&gt;
  booktitle = {AFRICACRYPT},&lt;br /&gt;
  year      = {2009},&lt;br /&gt;
  publisher = {Springer},&lt;br /&gt;
  editor = {Bart Preneel},&lt;br /&gt;
  note = {to appear},&lt;br /&gt;
  url = {http://www.131002.net/data/papers/ADMRT09.pdf},&lt;br /&gt;
  pages = {?},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Archive===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{vortexK+08,&lt;br /&gt;
  author    = {Lars R. Knudsen and Florian Mendel and Christian Rechberger and Søren S. Thomsen},&lt;br /&gt;
  title     = {Collision and Preimage Attacks on Vortex as submitted to the SHA-3 competition},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/5/5c/Vortex_Collisions_and_Preimages_note.txt},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{vortexAD08,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Orr Dunkelman},&lt;br /&gt;
  title     = {A note on Vortex' security},&lt;br /&gt;
  url        = {http://www.131002.net/data/papers/AD08.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  abstract = {Vortex is a hash function based on the AES that was presented at &lt;br /&gt;
ISC’2008, and submitted to the NIST SHA-3 competition after some modiﬁcations &lt;br /&gt;
that aim to strengthen it. This note ﬁrst shows that the original Vortex is not &lt;br /&gt;
collision-resistant, by describing an attack running in about 2^{58} compressions, in- &lt;br /&gt;
stead of $2^{128}$ ideally. In the new version submitted to NIST, we present several prop- &lt;br /&gt;
erties that seem to render it unsuitable for the new hash standard. In particular, &lt;br /&gt;
both versions of Vortex have the undesirable property of impossible images, which &lt;br /&gt;
gives distinguishers for a HMAC based on Vortex and slightly speeds up preimage &lt;br /&gt;
search.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=LUX&amp;diff=3013</id>
		<title>LUX</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=LUX&amp;diff=3013"/>
		<updated>2009-03-03T15:25:22Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Ivica Nikolić, Alex Biryukov, and Dmitry Khovratovich&lt;br /&gt;
* Website: [http://cryptolux.org/LUX  http://cryptolux.org/LUX]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/LUX.zip LUX.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3BiryukovKN,&lt;br /&gt;
  author    = {Ivica Nikolić, Alex Biryukov, and Dmitry Khovratovich},&lt;br /&gt;
  title     = {Hash family LUX - Algorithm Specifications and&lt;br /&gt;
Supporting Documentation},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/f/f3/LUX.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|   Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                      &lt;br /&gt;
|  | collision || reduced hash || 224 || 3 blank rounds || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | near-collision || reduced hash || 256 || 3 blank rounds || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | free-start collision || compression || ? ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | free-start preimage || compression || ? ||  || 2&amp;lt;sup&amp;gt;80&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf Wu,Feng,Wu]&lt;br /&gt;
|-                    &lt;br /&gt;
|  | slide-attack || hash || all || salt size: 31 mod 32 || - || - || [http://ehash.iaik.tugraz.at/uploads/6/62/Lux_peyrin.txt Peyrin]&lt;br /&gt;
|-                                      &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxWFW08,&lt;br /&gt;
  author    = {Shuang Wu and Dengguo Feng and Wenling Wu},&lt;br /&gt;
  title     = {Cryptanalysis of the Hash Function LUX-256},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/3/36/Analysis_LUX_1.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  abstract  = {LUX is a new hash function submitted to NIST's SHA-3 competition. In this paper, we found some non-random properties of LUX due to the weakness of origin shift vector. We also give reduced blank round collision attack, free-start collision attack and free-start preimage attack on LUX-256. The two collision attacks are trivial. The free-start preimage attack has complexity of about 2^{80} and requires negligible memory.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{luxP08,&lt;br /&gt;
  author    = {Thomas Peyrin},&lt;br /&gt;
  title     = {Slide attacks on LUX},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/6/62/Lux_peyrin.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Cheetah&amp;diff=3012</id>
		<title>Cheetah</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Cheetah&amp;diff=3012"/>
		<updated>2009-03-03T15:22:34Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Dmitry Khovratovich, Alex Biryukov, Ivica Nikolić&lt;br /&gt;
* Website: [http://cryptolux.org/Cheetah http://cryptolux.org/Cheetah]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Cheetah.zip Cheetah.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3KhovratovichBN08,&lt;br /&gt;
  author    = {Dmitry Khovratovich and Alex Biryukov and Ivica Nikolić},&lt;br /&gt;
  title     = {The Hash Function Cheetah: Speciﬁcation and Supporting Documentation},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/c/ca/Cheetah.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| length-extension || hash || all ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/d/d9/Cheetah_length-extension.txt Gligoroski]&lt;br /&gt;
|-                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{CheetahG08,&lt;br /&gt;
  author    = {Danilo Gligoroski},&lt;br /&gt;
  title     = {Cheetah hash function is not resistant against length-extension attack},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/d/d9/Cheetah_length-extension.txt},&lt;br /&gt;
  howpublished = {OFFICIAL COMMENT (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=MD6&amp;diff=3011</id>
		<title>MD6</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=MD6&amp;diff=3011"/>
		<updated>2009-03-03T15:16:29Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: 33 rounds of the MD6 permutation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Authors: Ron Rivest, Benjamin Agre, Daniel V. Bailey, Christopher Crutchfield, Yevgeniy Dodis, Kermin Elliott Fleming, Asif Khan, Jayant Krishnamurthy, Yuncheng Lin, Leo Reyzin, Emily Shen, Jim Sukha, Drew Sutherland, Eran Tromer, Yiqun Lisa Yin&lt;br /&gt;
* Website: [http://groups.csail.mit.edu/cis/md6/ http://groups.csail.mit.edu/cis/md6/] &lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/MD6.zip MD6.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Rivest08,&lt;br /&gt;
  author    = {Ronald L. Rivest},&lt;br /&gt;
  title     = {The MD6 hash function -- A proposal to NIST for SHA-3},&lt;br /&gt;
  url        = {http://groups.csail.mit.edu/cis/md6/submitted-2008-10-27/Supporting_Documentation/md6_report.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|   | non-randomness || reduced compression ||  || 18 rounds || ? || ? || [http://groups.csail.mit.edu/cis/md6/supmitted-2008-10-27/Supporting_Documentation/md6_report.pdf Aumasson,Meier]&lt;br /&gt;
|-                  &lt;br /&gt;
|  | key-recovery || reduced compression ||  || 15 rounds || ? || ? || [http://groups.csail.mit.edu/cis/md6/supmitted-2008-10-27/Supporting_Documentation/md6_report.pdf Dinur,Shamir]&lt;br /&gt;
|-              &lt;br /&gt;
|   | non-randomness || reduced permutation||  || 30 rounds || ? || ? || [http://www.dagstuhl.de/Materials/index.en.phtml?09031#Khovratovich,Dimitry Khovratovich]&lt;br /&gt;
|-  &lt;br /&gt;
|   | non-randomness || reduced permutation||  || 33 rounds || ? || ? || [http://fse2009rump.cr.yp.to/fe1a0e11287a9864c1d897a3110ebaa2.pdf, Khovratovich]&lt;br /&gt;
|-  &lt;br /&gt;
|   | collision || reduced compression ||  || 16 rounds || 2&amp;lt;sup&amp;gt;30&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/9/91/Khazaei_md6.txt Khazaei,Meier]&lt;br /&gt;
|-                           &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6AM08,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Willi Meier},&lt;br /&gt;
  title     = {Personal communication (nonrandomness on the reduced-round compression function)},&lt;br /&gt;
  url        = {http://groups.csail.mit.edu/cis/md6/submitted-2008-10-27/Supporting_Documentation/md6_report.pdf},&lt;br /&gt;
  howpublished = {Reported in the supporting documentation},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6DS08,&lt;br /&gt;
  author    = {Itai Dinur and Adi Shamir},&lt;br /&gt;
  title     = {Personal communication (key recovery on the reduced-round compression function)},&lt;br /&gt;
  url        = {http://groups.csail.mit.edu/cis/md6/submitted-2008-10-27/Supporting_Documentation/md6_report.pdf},&lt;br /&gt;
  howpublished = {Reported in the supporting documentation},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6K,&lt;br /&gt;
 author = {Dimitry Khovratovich},&lt;br /&gt;
 title = {Gaussian cryptanalysis of hash functions: collisions,&lt;br /&gt;
preimages, distinguishers},&lt;br /&gt;
 url = {http://www.dagstuhl.de/Materials/index.en.phtml?09031#Khovratovich,%20Dimitry},&lt;br /&gt;
 howpublished = {Available online, abstract only},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
 abstract = {Many attacks on hash functions can be reformulated in finding a hash &lt;br /&gt;
execution with constraints being fixed values of internal variables. Those &lt;br /&gt;
variables can be input or output bits, input of active S-boxes or AND &lt;br /&gt;
operations, etc.. &lt;br /&gt;
&lt;br /&gt;
The constraints lead to a system of nonlinear equations, which sometimes &lt;br /&gt;
can be solved with a fast algorithm resembling the Gaussian elimination. If a &lt;br /&gt;
system has been solved then solutions can be produced with negligible time &lt;br /&gt;
costs.&lt;br /&gt;
&lt;br /&gt;
The main condition for the algorithm to succeed is relatively slow diffusion in&lt;br /&gt;
 the attacked primitive. Provided this we show how to attack AES as a hash &lt;br /&gt;
function and prove that a 30-round MD6 compression function can be &lt;br /&gt;
distinguished from the random oracle.&lt;br /&gt;
&lt;br /&gt;
I will also show how it worked in practice in a GUI-tool.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6K2,&lt;br /&gt;
 author = {Dimitry Khovratovich},&lt;br /&gt;
 title = {Nonrandomness of the 33-round MD6},&lt;br /&gt;
 url = {http://fse2009rump.cr.yp.to/fe1a0e11287a9864c1d897a3110ebaa2.pdf},&lt;br /&gt;
 howpublished = {FSE 2009 rump session, slides only},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{cubehashA08,&lt;br /&gt;
  author    = {Shahram Khazaei and Willi Meier},&lt;br /&gt;
  title     = {Collisions for 16-round MD6},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/9/91/Khazaei_md6.txt}, &lt;br /&gt;
  howpublished = {NIST mailing list (local link)},&lt;br /&gt;
  year = {2009},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3004</id>
		<title>The SHA-3 Zoo</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=The_SHA-3_Zoo&amp;diff=3004"/>
		<updated>2009-03-02T14:12:32Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Collision and Preimage Attacks on Dynamic SHA&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The SHA-3 Zoo (work in progress) is a collection of cryptographic hash functions (in alphabetical order) submitted to the [http://www.nist.gov/hash-competition SHA-3 contest] (see also [http://en.wikipedia.org/wiki/SHA-3 here]). It aims to provide an overview of design and cryptanalysis of all submissions. A list of all [[SHA-3 submitters]] is also available. For a software performance related overview, see [http://bench.cr.yp.to/ebash.html eBASH]. At a separate page, we also collect [[SHA-3_Hardware_Implementations | hardware implementation results]] of the candidates. Another categorization of the SHA-3 submissions can be found [http://eprint.iacr.org/2008/511.pdf here].&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
The idea of the SHA-3 Zoo is to give a good overview of cryptanalytic results. We try to avoid additional judgement whether a submission is broken. The answer to this question is left to NIST. However, we categorize the cryptanalytic results by their impact from very theoretic to practical attacks. A detailed description is given in [[Cryptanalysis Categories]].&lt;br /&gt;
&lt;br /&gt;
At this time, 56 out of 64 submissions to the SHA-3 competition are publicly known and available. 51 [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/submissions_rnd1.html submissions] have advanced to the first round.&lt;br /&gt;
So far, 10 out of 51 first round candidates have been officially conceded broken or withdrawn by the designers.&lt;br /&gt;
&lt;br /&gt;
The following table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are collected at the individual hash function pages. A description of the main table is given [[Cryptanalysis_Categories#Main_Cryptanalysis_Table | here]].&lt;br /&gt;
&lt;br /&gt;
[http://ehash.iaik.tugraz.at/index.php?title=Special:Recentchangeslinked&amp;amp;target=The_SHA-3_Zoo&amp;amp;days=7&amp;amp;limit=50&amp;amp;hideminor=1 Recent updates of the SHA-3 Zoo]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot;| Best Attack on Main NIST Requirements !! width=&amp;quot;120&amp;quot;| Best Attack on other Hash Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[ARIRANG]]      || Jongin Lim || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[AURORA]]       || Masahiro Fujita  || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[BLAKE]]        || Jean-Philippe Aumasson || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Blender]]      || Colin Bradbury || style=&amp;quot;background:orange&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Blue Midnight Wish]] || Svein Johan Knapskog || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Cheetah]]      || Dmitry Khovratovich || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CHI]]          || Phillip Hawkes || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[CRUNCH]]       || Jacques Patarin || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[CubeHash]]     || Daniel J. Bernstein || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA]]  || Xu Zijie || style=&amp;quot;background:orange&amp;quot;|collision || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[Dynamic SHA2]] || Xu Zijie || || length-extension&lt;br /&gt;
|-&lt;br /&gt;
| [[ECHO]]         || Henri Gilbert || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ECOH]]         || Daniel R. L. Brown || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Edon-R (SHA-3 submission)|Edon-R]] || Danilo Gligoroski || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-&lt;br /&gt;
| [[EnRUPT]]       || Sean O’Neil || style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[ESSENCE]]      || Jason Worth Martin || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[FSB (SHA-3 submission) | FSB]] || Matthieu Finiasz || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Fugue]]        || Charanjit S. Jutla || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Groestl|Grøstl]] || Lars R. Knudsen || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Hamsi]]        || Ozgul Kucuk || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[JH]]           || Hongjun Wu || style=&amp;quot;background:greenyellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Keccak]]       || The Keccak Team || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LANE]]         || Sebastiaan Indesteege || ||&lt;br /&gt;
|-                         &lt;br /&gt;
| [[Lesamnta]]     || Hirotaka Yoshida || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Luffa]]        || Dai Watanabe || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[LUX]]          || Ivica Nikolic || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[MCSSHA-3]]     || Mikhail Maslennikov || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[MD6]]          || Ronald L. Rivest || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[NaSHA]]        || Smile Markovski || style=&amp;quot;background:orange&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SANDstorm]]    || Rich Schroeppel || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Sarmal]]       || Kerem Varici ||  style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Sgàil]]        || Peter Maxwell|| style=&amp;quot;background:red&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Shabal]]       || Jean-Francois Misarsky || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SHAvite-3]]    || Orr Dunkelman || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SIMD]]         || Gaetan Leurent || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Skein]]        || Bruce Schneier || ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Spectral Hash]] || Cetin Kaya Koc || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[SWIFFTX]]      || Daniele Micciancio || ||&lt;br /&gt;
|-&lt;br /&gt;
| [[TIB3]]         || Daniel Penazzi || style=&amp;quot;background:yellow&amp;quot; | collision ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Twister]]      || Michael Gorski || style=&amp;quot;background:yellow&amp;quot; | 2nd preimage ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[Vortex (SHA-3 submission)|Vortex]] || Michael Kounavis || style=&amp;quot;background:yellow&amp;quot; | preimage ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following hash functions have been submitted to the NIST competition but did not advance to the first round, or have been conceded broken or withdrawn by the designers:&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;120&amp;quot;| Hash Name !! width=&amp;quot;160&amp;quot; | Principal Submitter !! width=&amp;quot;120&amp;quot; | Status !! width=&amp;quot;120&amp;quot; | Best Attack on Main NIST Requirements&lt;br /&gt;
|-&lt;br /&gt;
| [[Abacus]]      || Neil Sholer || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Boole]]       || Greg Rose || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[DCH]]         || David A. Wilson || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[HASH 2X]]     || Jason Lee || not in round 1 || style=&amp;quot;background:red&amp;quot; | 2nd-preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[Khichidi-1]]  || M. Vidyasagar || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Maraca]]      || Robert J. Jenkins || not in round 1 || style=&amp;quot;background:red&amp;quot; | preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[MeshHash]]    || Björn Fay || conceded broken || style=&amp;quot;background:orange&amp;quot; | 2nd preimage&lt;br /&gt;
|-&lt;br /&gt;
| [[NKS2D]]       || Geoffrey Park || not in round 1 || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Ponic]]       || Peter Schmidt-Nielsen || not in round 1 || style=&amp;quot;background:yellow&amp;quot; | 2nd-preimage&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
| [[SHAMATA]]      || Orhun Kara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-                         &lt;br /&gt;
| [[StreamHash]]   || Michal Trojnara || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Tangle]]      || Rafael Alvarez || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[WaMM]]        || John Washburn || conceded broken || style=&amp;quot;background:red&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[Waterfall]]   || Bob Hattersley || conceded broken || style=&amp;quot;background:orange&amp;quot; | collision&lt;br /&gt;
|-&lt;br /&gt;
| [[ZK-Crypt]]       || Carmi Gressel || not in round 1 ||&lt;br /&gt;
|-                                                                                                             &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Your analysis is not mentioned? Drop a line at sha3zoo@iaik.tugraz.at to let us know!&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Dynamic_SHA&amp;diff=3003</id>
		<title>Dynamic SHA</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Dynamic_SHA&amp;diff=3003"/>
		<updated>2009-03-02T14:10:41Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: Collision and Preimage Attacks on Dynamic SHA&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Zijie Xu&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* Website:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/DyamicSHA.zip DyamicSHA.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Xu08,&lt;br /&gt;
  author    = {Zijie Xu},&lt;br /&gt;
  title     = {Dynamic SHA},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/e/e2/DyamicSHA.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot; | collision|| hash || 256||  || 2&amp;lt;sup&amp;gt;114&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/c/c2/Dsha.pdf Indesteege]&lt;br /&gt;
|-                   &lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot; | collision|| hash || 512||  || 2&amp;lt;sup&amp;gt;170&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/c/c2/Dsha.pdf Indesteege]&lt;br /&gt;
|-    &lt;br /&gt;
|  preimage|| compression|| 256||  || 2&amp;lt;sup&amp;gt;216&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/c/c2/Dsha.pdf Indesteege]&lt;br /&gt;
|-     &lt;br /&gt;
|  preimage|| compression|| 512||  || 2&amp;lt;sup&amp;gt;256&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/c/c2/Dsha.pdf Indesteege]&lt;br /&gt;
|-              &lt;br /&gt;
| length-extension || hash || all ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/e/e7/Dynamic-sha_length-extension.txt Klima]&lt;br /&gt;
|-                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{DynamicSHAI09,&lt;br /&gt;
  author    = {Sebastiaan Indesteege},&lt;br /&gt;
  title     = {Cryptanalysis of Dynamic SHA},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/c/c2/Dsha.pdf},&lt;br /&gt;
  howpublished = {presentation slides available online (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{DynamicSHAK08,&lt;br /&gt;
  author    = {Vlastimil Klima},&lt;br /&gt;
  title     = {Dynamic SHA is vulnerable to generic attacks},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/e/e7/Dynamic-sha_length-extension.txt},&lt;br /&gt;
  howpublished = {OFFICIAL COMMENT (local link)},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=File:Dsha.pdf&amp;diff=3002</id>
		<title>File:Dsha.pdf</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=File:Dsha.pdf&amp;diff=3002"/>
		<updated>2009-03-02T14:08:07Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Edon-R_(SHA-3_submission)&amp;diff=2938</id>
		<title>Edon-R (SHA-3 submission)</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Edon-R_(SHA-3_submission)&amp;diff=2938"/>
		<updated>2009-02-11T07:51:23Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added V. Klima as co-author&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Danilo Gligoroski, Rune Steinsmo Ødegård, Marija Mihova, Svein Johan Knapskog, Ljupco Kocarev, Aleš Drápal, Vlastimil Klima&lt;br /&gt;
* Website: [http://www.item.ntnu.no/people/personalpages/fac/danilog/edon-r http://www.item.ntnu.no/people/personalpages/fac/danilog/edon-r]&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/EDON-R.zip EDON-R.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3G+08,&lt;br /&gt;
  author    = {Danilo Gligoroski and Rune Steinsmo Ødegård and Marija Mihova and Svein Johan Knapskog and Ljupco Kocarev and Aleš Drápal and Vlastimil Klima},&lt;br /&gt;
  title     = {Cryptographic Hash Function EDON-R},&lt;br /&gt;
  url        = {http://people.item.ntnu.no/~danilog/Hash/Edon-R/Supporting_Documentation/EdonRDocumentation.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
| Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                    &lt;br /&gt;
| style=&amp;quot;background:yellow&amp;quot; | preimage || hash ||  ||  || 2&amp;lt;sup&amp;gt;2n/3&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;2n/3&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/7/74/Edon.pdf Khovratovich,Nikolić,Weinmann]&lt;br /&gt;
|-                    &lt;br /&gt;
| multi-collision (2&amp;lt;sup&amp;gt;K&amp;lt;/sup&amp;gt;) || hash || 256,512 ||  || K*2&amp;lt;sup&amp;gt;n/2&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;n/2&amp;lt;/sup&amp;gt; || [http://cryptography.hyperlink.cz/BMW/EDONR_analysis_vk.pdf Klima]&lt;br /&gt;
|-                    &lt;br /&gt;
| multi-preimage || hash || 256,512 ||  || ? || ? || [http://cryptography.hyperlink.cz/BMW/EDONR_analysis_vk.pdf Klima]&lt;br /&gt;
|-&lt;br /&gt;
| collision || compression ||  ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/7/74/Edon.pdf Khovratovich,Nikolić,Weinmann]&lt;br /&gt;
|-                    &lt;br /&gt;
| 2nd preimage || compression ||  ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/7/74/Edon.pdf Khovratovich,Nikolić,Weinmann]&lt;br /&gt;
|-                    &lt;br /&gt;
| preimage || compression ||  ||  || - || - || [http://ehash.iaik.tugraz.at/uploads/7/74/Edon.pdf Khovratovich,Nikolić,Weinmann]&lt;br /&gt;
|-                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{edonKNW08,&lt;br /&gt;
  author    = {Dmitry Khovratovich and Ivica Nikolić and Ralf-Philipp Weinmann},&lt;br /&gt;
  title     = {Cryptanalysis of Edon-R},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/7/74/Edon.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  abstract  = {We present various types of attacks on the hash family Edon-R. In a free start attack scenario, with the initial chaining value not xored, all three main attacks (collisions, second preimage, and preimage) can be launched on Edon-R with negligible effort. In these attacks we exploit the asymmetrical diffusion of the chaining values in the compression function. Also, by partially inverting the compression function and xoring one part of the chaining value, we launch a meet-in-the-middle attack on Edon-R-n to find real preimages. The attack requires $2^{2n/3}$ effort and the same amount of memory. The attacks are applicable to all digest sizes.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{edonK08,&lt;br /&gt;
  author    = {Vlastimil Klima},&lt;br /&gt;
  title     = {Multicollisions of EDON-R hash function and other observations},&lt;br /&gt;
  url        = {http://cryptography.hyperlink.cz/BMW/EDONR_analysis_vk.pdf},&lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
  abstract  = {The main principle how to make n-bit EDON-R hash functions [1] resistant to generic multicollisions and multipreimages attacks ([2], [3]) is the 2n-bit width of internal chaining value. We show how to degenerate 2n-bit chaining value to n-bit chaining value (for n = 256, 512) by keeping the half of chaining value constant from the beginning. It circumvents the main principle and make EDON-R hash functions (for n = 256, 512) vulnerable to generic multicollisions and multipreimages attacks ([2], [3]) with small additional work factor. We show several properties of EDON-R compression function, which could be interesting for the next study of collisions and preimages. The first cryptanalysis of EDON-R was made in [4]. We present an independent research, partially overlaping with [4]. We want to note that this is preliminary version, that we present here only sketches of the proofs and that not all of the accompanied problems are completely solved.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Maraca&amp;diff=2895</id>
		<title>Maraca</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Maraca&amp;diff=2895"/>
		<updated>2009-01-13T12:31:38Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Robert J. Jenkins Jr.&lt;br /&gt;
* Website: [http://burtleburtle.net/bob/crypto/maraca/nist/ http://burtleburtle.net/bob/crypto/maraca/nist/]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Jenkins08,&lt;br /&gt;
  author    = {Robert J. Jenkins Jr.},&lt;br /&gt;
  title     = {Algorithm Specification},&lt;br /&gt;
  url        = {http://burtleburtle.net/bob/crypto/maraca/nist/Supporting_Documentation/specification.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|  style=&amp;quot;background:yellow&amp;quot; | collision || internal state || 512 ||  || 2&amp;lt;sup&amp;gt;237&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;230.5&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/5/52/Maraca.pdf Canteaut,Naya-Plasencia]&lt;br /&gt;
|-   &lt;br /&gt;
|  style=&amp;quot;background:red&amp;quot; | preimage|| hash || 512 ||  || ? || ? || [http://homes.esat.kuleuven.be/~sindeste/maraca.html Indesteege]&lt;br /&gt;
|-                                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{maracaCN08,&lt;br /&gt;
 author = {Anne Canteaut and María Naya-Plasencia},&lt;br /&gt;
 title = {Internal collision attack on Maraca},&lt;br /&gt;
 url = {http://ehash.iaik.tugraz.at/uploads/5/52/Maraca.pdf},&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2008},&lt;br /&gt;
 abstract = {We present an internal collision attack against the new hash&lt;br /&gt;
function Maraca which has been submitted to the SHA-3 competition.&lt;br /&gt;
This attack requires 2^{237} calls to the round function and its complexity is&lt;br /&gt;
lower than the complexity of the generic collision attack when the length&lt;br /&gt;
of the message digest is greater than or equal to 512. The cryptanalysis&lt;br /&gt;
mainly exploits two features of Maraca: the fact that the message block&lt;br /&gt;
inserted at each round has the same size as the internal state, and some&lt;br /&gt;
particular differential properties of the inner permutation.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{maracaI09,&lt;br /&gt;
 author = {Sebastiaan Indesteege},&lt;br /&gt;
 title = {Practical Preimages for Maraca},&lt;br /&gt;
 url = {http://homes.esat.kuleuven.be/~sindeste/maraca.html},&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
 abstract = {We show a practical (seconds on a PC) preimage attack on the hash function Maraca.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Maraca&amp;diff=2890</id>
		<title>Maraca</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Maraca&amp;diff=2890"/>
		<updated>2009-01-11T14:18:56Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Robert J. Jenkins Jr.&lt;br /&gt;
* Website: [http://burtleburtle.net/bob/crypto/maraca/nist/ http://burtleburtle.net/bob/crypto/maraca/nist/]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Jenkins08,&lt;br /&gt;
  author    = {Robert J. Jenkins Jr.},&lt;br /&gt;
  title     = {Algorithm Specification},&lt;br /&gt;
  url        = {http://burtleburtle.net/bob/crypto/maraca/nist/Supporting_Documentation/specification.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|  style=&amp;quot;background:yellow&amp;quot; | collision || internal state || 512 ||  || 2&amp;lt;sup&amp;gt;237&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;230.5&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/5/52/Maraca.pdf Canteaut,Naya-Plasencia]&lt;br /&gt;
|-   &lt;br /&gt;
|  style=&amp;quot;background:orange&amp;quot; | preimage|| hash || 512 ||  || ? || ? || [http://www.dagstuhl.de/Materials/index.en.phtml?09031#Indesteege,%20Sebastiaan Indesteege]&lt;br /&gt;
|-                                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{maracaCN08,&lt;br /&gt;
 author = {Anne Canteaut and María Naya-Plasencia},&lt;br /&gt;
 title = {Internal collision attack on Maraca},&lt;br /&gt;
 url = {http://ehash.iaik.tugraz.at/uploads/5/52/Maraca.pdf},&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2008},&lt;br /&gt;
 abstract = {We present an internal collision attack against the new hash&lt;br /&gt;
function Maraca which has been submitted to the SHA-3 competition.&lt;br /&gt;
This attack requires 2^{237} calls to the round function and its complexity is&lt;br /&gt;
lower than the complexity of the generic collision attack when the length&lt;br /&gt;
of the message digest is greater than or equal to 512. The cryptanalysis&lt;br /&gt;
mainly exploits two features of Maraca: the fact that the message block&lt;br /&gt;
inserted at each round has the same size as the internal state, and some&lt;br /&gt;
particular differential properties of the inner permutation.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{maracaI09,&lt;br /&gt;
 author = {Sebastiaan Indesteege},&lt;br /&gt;
 title = {Practical Preimages for Maraca},&lt;br /&gt;
 url = {http://www.dagstuhl.de/Materials/index.en.phtml?09031#Indesteege,%20Sebastiaan},&lt;br /&gt;
 howpublished = {Available online, abstract only},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
 abstract = {We show a practical (seconds on a PC) preimage attack on the hash function Maraca.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=MD6&amp;diff=2889</id>
		<title>MD6</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=MD6&amp;diff=2889"/>
		<updated>2009-01-11T11:43:15Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: added new distinguisher&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Authors: Ron Rivest, Benjamin Agre, Daniel V. Bailey, Christopher Crutchfield, Yevgeniy Dodis, Kermin Elliott Fleming, Asif Khan, Jayant Krishnamurthy, Yuncheng Lin, Leo Reyzin, Emily Shen, Jim Sukha, Drew Sutherland, Eran Tromer, Yiqun Lisa Yin&lt;br /&gt;
* Website: [http://groups.csail.mit.edu/cis/md6/ http://groups.csail.mit.edu/cis/md6/] &lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/MD6.zip MD6.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Rivest08,&lt;br /&gt;
  author    = {Ronald L. Rivest},&lt;br /&gt;
  title     = {The MD6 hash function -- A proposal to NIST for SHA-3},&lt;br /&gt;
  url        = {http://groups.csail.mit.edu/cis/md6/submitted-2008-10-27/Supporting_Documentation/md6_report.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                      &lt;br /&gt;
|   | non-randomness || reduced compression ||  || 30 rounds || ? || ? || [http://www.dagstuhl.de/Materials/index.en.phtml?09031#Khovratovich,%20Dimitry Khovratovich]&lt;br /&gt;
|-    &lt;br /&gt;
|   | non-randomness || reduced compression ||  || 18 rounds || ? || ? || [http://groups.csail.mit.edu/cis/md6/supmitted-2008-10-27/Supporting_Documentation/md6_report.pdf Aumasson,Meier]&lt;br /&gt;
|-                  &lt;br /&gt;
|  | key-recovery || reduced compression ||  || 15 rounds || ? || ? || [http://groups.csail.mit.edu/cis/md6/supmitted-2008-10-27/Supporting_Documentation/md6_report.pdf Dinur,Shamir]&lt;br /&gt;
|-                                       &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6AM08,&lt;br /&gt;
  author    = {Jean-Philippe Aumasson and Willi Meier},&lt;br /&gt;
  title     = {Personal communication (nonrandomness on the reduced-round compression function)},&lt;br /&gt;
  url        = {http://groups.csail.mit.edu/cis/md6/submitted-2008-10-27/Supporting_Documentation/md6_report.pdf},&lt;br /&gt;
  howpublished = {Reported in the supporting documentation},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6DS08,&lt;br /&gt;
  author    = {Itai Dinur and Adi Shamir},&lt;br /&gt;
  title     = {Personal communication (key recovery on the reduced-round compression function)},&lt;br /&gt;
  url        = {http://groups.csail.mit.edu/cis/md6/submitted-2008-10-27/Supporting_Documentation/md6_report.pdf},&lt;br /&gt;
  howpublished = {Reported in the supporting documentation},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{md6K,&lt;br /&gt;
 author = {Dimitry Khovratovich},&lt;br /&gt;
 title = {Gaussian cryptanalysis of hash functions: collisions,&lt;br /&gt;
preimages, distinguishers},&lt;br /&gt;
 url = {http://www.dagstuhl.de/Materials/index.en.phtml?09031#Khovratovich,%20Dimitry},&lt;br /&gt;
 howpublished = {Available online, abstract only},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
 abstract = {Many attacks on hash functions can be reformulated in finding a hash &lt;br /&gt;
execution with constraints being fixed values of internal variables. Those &lt;br /&gt;
variables can be input or output bits, input of active S-boxes or AND &lt;br /&gt;
operations, etc.. &lt;br /&gt;
&lt;br /&gt;
The constraints lead to a system of nonlinear equations, which sometimes &lt;br /&gt;
can be solved with a fast algorithm resembling the Gaussian elimination. If a &lt;br /&gt;
system has been solved then solutions can be produced with negligible time &lt;br /&gt;
costs.&lt;br /&gt;
&lt;br /&gt;
The main condition for the algorithm to succeed is relatively slow diffusion in&lt;br /&gt;
 the attacked primitive. Provided this we show how to attack AES as a hash &lt;br /&gt;
function and prove that a 30-round MD6 compression function can be &lt;br /&gt;
distinguished from the random oracle.&lt;br /&gt;
&lt;br /&gt;
I will also show how it worked in practice in a GUI-tool.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Maraca&amp;diff=2888</id>
		<title>Maraca</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Maraca&amp;diff=2888"/>
		<updated>2009-01-11T11:22:44Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: new preimage attack&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Robert J. Jenkins Jr.&lt;br /&gt;
* Website: [http://burtleburtle.net/bob/crypto/maraca/nist/ http://burtleburtle.net/bob/crypto/maraca/nist/]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3Jenkins08,&lt;br /&gt;
  author    = {Robert J. Jenkins Jr.},&lt;br /&gt;
  title     = {Algorithm Specification},&lt;br /&gt;
  url        = {http://burtleburtle.net/bob/crypto/maraca/nist/Supporting_Documentation/specification.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|  style=&amp;quot;background:yellow&amp;quot; | collision || internal state || 512 ||  || 2&amp;lt;sup&amp;gt;237&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;230.5&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/5/52/Maraca.pdf Canteaut,Naya-Plasencia]&lt;br /&gt;
|-   &lt;br /&gt;
|  style=&amp;quot;background:red&amp;quot; | preimage|| hash || 512 ||  || ? || ? || [http://www.dagstuhl.de/Materials/index.en.phtml?09031#Indesteege,%20Sebastiaan Indesteege]&lt;br /&gt;
|-                                    &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{maracaCN08,&lt;br /&gt;
 author = {Anne Canteaut and María Naya-Plasencia},&lt;br /&gt;
 title = {Internal collision attack on Maraca},&lt;br /&gt;
 url = {http://ehash.iaik.tugraz.at/uploads/5/52/Maraca.pdf},&lt;br /&gt;
 howpublished = {Available online},&lt;br /&gt;
 year = {2008},&lt;br /&gt;
 abstract = {We present an internal collision attack against the new hash&lt;br /&gt;
function Maraca which has been submitted to the SHA-3 competition.&lt;br /&gt;
This attack requires 2^{237} calls to the round function and its complexity is&lt;br /&gt;
lower than the complexity of the generic collision attack when the length&lt;br /&gt;
of the message digest is greater than or equal to 512. The cryptanalysis&lt;br /&gt;
mainly exploits two features of Maraca: the fact that the message block&lt;br /&gt;
inserted at each round has the same size as the internal state, and some&lt;br /&gt;
particular differential properties of the inner permutation.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{maracaI09,&lt;br /&gt;
 author = {Sebastiaan Indesteege},&lt;br /&gt;
 title = {Practical Preimages for Maraca},&lt;br /&gt;
 url = {http://www.dagstuhl.de/Materials/index.en.phtml?09031#Indesteege,%20Sebastiaan},&lt;br /&gt;
 howpublished = {Available online, abstract only},&lt;br /&gt;
 year = {2009},&lt;br /&gt;
 abstract = {We show a practical (seconds on a PC) preimage attack on the hash functin Maraca.},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Cryptanalysis_Categories&amp;diff=2862</id>
		<title>Cryptanalysis Categories</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Cryptanalysis_Categories&amp;diff=2862"/>
		<updated>2008-12-30T13:43:42Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For presentation reasons, we provide a ''simplified'' overview of cryptanalytic results in The SHA-3 Zoo. We only consider cryptanalytic results that have not been performed by the designers themselves and are included in the initial proposal. Exceptions are cryptanalytic results by non-designers and cryptanalytic results by designers that are not mentioned in the proposal.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Color Codes ==&lt;br /&gt;
&lt;br /&gt;
Different color codes should give a better overview of the impact of cryptanalytic results. The color codes are only used for results on the main  NIST requirements of the full hash function with recommended parameters. &lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;100&amp;quot;| color !! Complexity of Result !! Explanation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:greenyellow&amp;quot;  |  || compr. calls &amp;lt; generic || align=&amp;quot;left&amp;quot; | The number of compression function calls (or equivalents) is below generic attacks for collision, 2nd preimage or preimage. The complexity of the attack is very close to generic attacks and is therefore of lesser relevance. Additionally, attacks in this simple model may neglect memory considerations. However, attacks of this type do not exist for the SHA-2 hash functions. &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:yellow&amp;quot; | || compr. calls &amp;lt; generic * 1/n  || align=&amp;quot;left&amp;quot; | The number of compression function calls (or equivalents) is below generic attacks reduced by a factor of n (hash size) for collision, 2nd preimage or preimage. Attacks in this simple model may neglect memory considerations. However, attacks of this type do not exist for the SHA-2 hash functions.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:orange&amp;quot; | || time*memory &amp;lt; generic     || align=&amp;quot;left&amp;quot; | The time*memory product is below generic attacks for collision, 2nd preimage or preimage. &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:red&amp;quot; |    || practical example         || align=&amp;quot;left&amp;quot; | A practical example is given for the attack on this hash function. This is an extra category since practical examples improve the confidence in an attack.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Main Cryptanalysis Table ==&lt;br /&gt;
&lt;br /&gt;
The main table should give a first impression on the remaining SHA-3 candidates. It shows only the best known attack, more detailed results are given in the individual hash function tables.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;140&amp;quot;| column !! Explanation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Hash Name                 || align=&amp;quot;left&amp;quot; | More detailed information about this SHA-3 candidate is given at its WikiPage.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Principal Submitter       || align=&amp;quot;left&amp;quot; | This column shows only the principal submitter. Additional contributors are listed at the individual hash function pages and all submitters are listed [http://ehash.iaik.tugraz.at/wiki/SHA-3_submitters here].&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Best Attack on Main NIST Requirements  || align=&amp;quot;left&amp;quot; | In this column the best attack on collision, 2nd-preimage and preimage resistant is shown. To give a quick overview of the complexity of the best attack, the cells are labeled with different colors.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Best Attack on other Hash Requirements || align=&amp;quot;left&amp;quot; | Best Attack on additional requirements for a hash function not unambiguously specified by NIST yet.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Individual Hash Function Tables ==&lt;br /&gt;
&lt;br /&gt;
The individual hash function tables give a more detailed overview of the cryptanalytic results with its complexity. A dash (-) in the individual table means that the complexities are neglible. A question mark (?) means that the information is not given or unclear. We ask the authors to include these results in the abstract of their publication.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;&lt;br /&gt;
! width=&amp;quot;140&amp;quot;| column !! Explanation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Type of Analysis    || align=&amp;quot;left&amp;quot; | This column gives a first impression what (requirement) has been analyzed. Some results do not violate any security requirements. Only attacks on the main NIST requirements and for the full hash function with recommended parameters are highlighted.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Hash Function Part  || align=&amp;quot;left&amp;quot; | Shows which part of the hash function has been attacked.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Hash Size (n)       || align=&amp;quot;left&amp;quot; | The hash sizes for which the attack applies with the given complexity.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Parameters/Variants || align=&amp;quot;left&amp;quot; | Gives the parameters for attacks on reduced variants. The column is left empty if the attack is on the recommended parameters of the designers.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Compression Function Calls || align=&amp;quot;left&amp;quot; | The number of compression function calls (or equivalents) as given by the authors.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Memory Requirements || align=&amp;quot;left&amp;quot; | The memory requirements of the attack as given by the authors.&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;background:#efefef;&amp;quot;| Reference           || align=&amp;quot;left&amp;quot; | A link the published result.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
	<entry>
		<id>https://ehash.iaik.tugraz.at/index.php?title=Twister&amp;diff=2861</id>
		<title>Twister</title>
		<link rel="alternate" type="text/html" href="https://ehash.iaik.tugraz.at/index.php?title=Twister&amp;diff=2861"/>
		<updated>2008-12-30T13:41:51Z</updated>

		<summary type="html">&lt;p&gt;Crechberger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== The algorithm ==&lt;br /&gt;
&lt;br /&gt;
* Author(s): Ewan Fleischmann, Christian Forler and Michael Gorski&lt;br /&gt;
* Website: http://www.twister-hash.com&lt;br /&gt;
* NIST submission package: [http://csrc.nist.gov/groups/ST/hash/sha-3/Round1/documents/Twister.zip Twister.zip]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{sha3FleischmannFG08,&lt;br /&gt;
  author    = {Ewan Fleischmann, Christian Forler and Michael Gorski},&lt;br /&gt;
  title     = {The Twister Hash Function Family},&lt;br /&gt;
  url        = {http://ehash.iaik.tugraz.at/uploads/3/39/Twister.pdf},&lt;br /&gt;
  howpublished = {Submission to NIST},&lt;br /&gt;
  year      = {2008},&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Cryptanalysis ==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;4&amp;quot; cellspacing=&amp;quot;0&amp;quot; class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;                   &lt;br /&gt;
|- style=&amp;quot;background:#efefef;&amp;quot;                   &lt;br /&gt;
|    Type of Analysis || Hash Function Part || Hash Size (n) || Parameters/Variants || Compression Function Calls || Memory Requirements ||   Reference &lt;br /&gt;
|-                                        &lt;br /&gt;
|  | pseudo-collision || compression || all ||  || 2&amp;lt;sup&amp;gt;26.5&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;28&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/d/dd/Twister_attack.pdf Mendel,Rechberger,Schläffer]&lt;br /&gt;
|-                    &lt;br /&gt;
|  style=&amp;quot;background:greenyellow&amp;quot; | collision || hash || 512 ||  || 2&amp;lt;sup&amp;gt;252&amp;lt;/sup&amp;gt; || - || [http://ehash.iaik.tugraz.at/uploads/d/dd/Twister_attack.pdf Mendel,Rechberger,Schläffer]&lt;br /&gt;
|-                    &lt;br /&gt;
|  style=&amp;quot;background:yellow&amp;quot; | 2nd preimage || hash || 512 ||  || 2&amp;lt;sup&amp;gt;448&amp;lt;/sup&amp;gt; || 2&amp;lt;sup&amp;gt;64&amp;lt;/sup&amp;gt; || [http://ehash.iaik.tugraz.at/uploads/d/dd/Twister_attack.pdf Mendel,Rechberger,Schläffer]&lt;br /&gt;
|-                                        &lt;br /&gt;
|}                    &lt;br /&gt;
&lt;br /&gt;
A description of this table is given [http://ehash.iaik.tugraz.at/wiki/Cryptanalysis_Categories#Individual_Hash_Function_Tables here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bibtex&amp;gt;&lt;br /&gt;
@misc{twisterMRS08,&lt;br /&gt;
  author    = {Florian Mendel and Christian Rechberger and Martin Schläffer},&lt;br /&gt;
  title     = {Cryptanalysis of Twister},&lt;br /&gt;
  url = {http://ehash.iaik.tugraz.at/uploads/d/dd/Twister_attack.pdf}, &lt;br /&gt;
  howpublished = {Available online},&lt;br /&gt;
  year = {2008},&lt;br /&gt;
  abstract = {In this paper, we present a pseudo-collision attack on the compression function of all&lt;br /&gt;
Twister variants (224,256,384,512) with complexity of about 2^26.5 compression function evalua-&lt;br /&gt;
tions. We show how the compression function attack can be extended to construct collisions for&lt;br /&gt;
Twister-512 slightly faster than brute force search. Furthermore, we present a second-preimage at-&lt;br /&gt;
tack for Twister-512 with complexity of about 2^448 compression function evaluations and memory&lt;br /&gt;
requirement of 2^64.&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/bibtex&amp;gt;&lt;/div&gt;</summary>
		<author><name>Crechberger</name></author>
		
	</entry>
</feed>