Higher-Order Differential Attack on Reduced SHA-256.
Mario Lamberger, Florian Mendel · IACR Cryptology ePrint Archive · 2011
In this work, we study the application of higher-order differential attacks on hash functions. We show a second-order differential attack on the SHA-256 compression function reduced to 46 out of 64 steps. We implemented the attack and give the result in Table 1. The best attack so far (in a different attack model) with practical complexity was for 33 steps of the compression function.