Practical Near-Collisions and Collisions on Round-Reduced ECHO-256 Compression Function

@article{Jean2010PracticalNA,
  title={Practical Near-Collisions and Collisions on Round-Reduced ECHO-256 Compression Function},
  author={J{\'e}r{\'e}my Jean and Pierre-Alain Fouque},
  journal={IACR Cryptology ePrint Archive},
  year={2010},
  volume={2010},
  pages={569}
}
In this paper, we present new results on the second-round SHA-3 candidate ECHO. We describe a method to construct a collision in the compression function of ECHO-256 reduced to four rounds in 2 operations on AES-columns without significant memory requirements. Our attack uses the most recent analyses on ECHO, in particular the SuperSBox and SuperMixColumns layers to utilize efficiently the available freedom degrees. We also show why some of these results are flawed and we propose a solution to… CONTINUE READING