Projects per year
Abstract
Hash functions and extendable output functions are some of the most fundamental building blocks in cryptography. They are often used to build commitment schemes where a committer binds themselves to some value that is also hidden from the verifier until the opening is sent. Such commitment schemes are commonly used to build signature schemes, e.g., Ed25519 via Schnorr signatures, or non-interactive zero-knowledge proofs. We specifically analyze the binding security when Ascon-Hash256 or Ascon-XOF128 is used inside of Ed25519, which is closely related to finding second preimages. While there is ample prior work on Ascon-XOF128 and Ascon-Hash256, none of it applies in this setting either because it analyzes short outputs of 64 or 128 bits or because the complexity is above the security claim and generic attack of 128 bits. We show how to exploit the setting of finding a forgery for Ed25519. We find that this setting is quite challenging due to the large 320-bit internal state combined with the 128-bit security level. We propose a second-preimage attack for 1-round Ascon-Hash256 with a complexity of 2 64 Gaussian eliminations and a random-prefix-preimage attack (also known as Nostradamus attack) for 1-round Ascon-Hash256, for the Ed25519 setting, with complexity 2 29.7 Gaussian eliminations.
| Original language | English |
|---|---|
| Title of host publication | Selected Areas in Cryptography - SAC 2025 - 32nd International Conference, Revised Selected Papers |
| Editors | Christina Boura, Atefeh Mashatan, Ali Miri |
| Publisher | Springer |
| Pages | 3-25 |
| Number of pages | 23 |
| ISBN (Print) | 9783032105356 |
| DOIs | |
| Publication status | Published - Jan 2026 |
Publication series
| Name | Lecture Notes in Computer Science |
|---|---|
| Volume | 16207 LNCS |
| ISSN (Print) | 0302-9743 |
| ISSN (Electronic) | 1611-3349 |
Keywords
- Digital Signatures
- Hash Functions
- Preimage Attacks
ASJC Scopus subject areas
- Theoretical Computer Science
- General Computer Science
Fields of Expertise
- Information, Communication & Computing
Treatment code (Nähere Zuordnung)
- Basic - Fundamental (Grundlagenforschung)
Projects
- 1 Active
-
EU - KEYLESS - Keyless Cryptography for Efficiency and Security
Eichlseder, M. (Project manager on research unit)
1/01/25 → 31/12/29
Project: Research project
-
Preimage-type Attacks for Reduced Ascon-Hash: Application to Ed25519
Nageler, M. (Speaker)
13 Aug 2025Activity: Talk or presentation › Talk at conference or symposium › Science to science
-
Preimage-Type Attacks for Reduced Ascon-Hash: Application to Ed25519
Nageler, M. (Speaker)
6 Nov 2025Activity: Talk or presentation › Talk at workshop, seminar or course › Science to science
Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS