Cryptanalysis of the 10-Round Hash and Full Compression Function of SHAvite-3-512

Authors: P.Gauravaram, G.Leurent, F.Mendel, M.Naya-Plasencia, T.Peyrin, C.Rechberger, M.Schläffer

Abstract: We analyze the SHAvite-3-512 hash function, as proposed and tweaked for round 2 of the SHA-3 competition. We present cryptanalytic results on 10 out of 14 rounds of the hash function SHAvite-3-512, and on the full 14 round compression function of SHAvite-3-512. We show a second preimage attack on the hash function reduced to 10 rounds with a complexity of 2497 compression function evaluations and 216 memory. For the full 14-round compression function, we give a chosen counter, chosen salt preimage attack with 2384 compression function evaluations and 2128 memory (or complexity 2448 without memory), and a collision attack with 2192 compression function evaluations and 2128 memory.

Keywords: Hash function, Cryptanalysis, Collision and (second) preimage.