Cryptanalysis of 1-Round KECCAK


In this paper, we give the first pre-image attack against 1round KECCAK-512 hash function, which works for all variants of 1round KECCAK. The attack gives a preimage of length less than 1024 bits by solving a system of 384 linear equations. We also give a collision attack against 1-round KECCAK using similar analysis. 
DOI: 10.1007/978-3-319-89339-6_8


