International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 22 September 2026

Yufei Yuan, Ruichen Wu, Shanpeng Wei, Junxu Shen, Jinpeng Liu, Yixin Zhang
ePrint Report ePrint Report
The Institute of Commercial Cryptography Standards (ICCS) launched the Next-generation Commercial Cryptographic Algorithms Program (NGCC) and invited worldwide comments on draft submission requirements and evaluation criteria for cryptographic hash algorithms. Our analysis of seven submitted hash functions gives the following results:

- Message differences that cancel in every key injection give explicit collisions for all four fixed-output variants of \textbf{MoFang} and both XOF variants at every finite output length. - Two distinct states of \textbf{Neulaser} become equal after one update, giving collisions for all three variants with the initialization used by the v2 reference and optimized implementations. - An invariant subspace of \textbf{CHIME-512} permits collision search using at most \(2^{64}\) hash evaluations when shifts act separately on 64-bit words, as in both submitted implementations. - \textbf{CHAMP}'s determinant constraint gives collision searches using at most \(2^{192}\) and \(2^{384}\) hash evaluations for its 512- and 1024-bit variants, respectively. - The core permutation of \textbf{QSH} acts on \(64w\) bits and preserves a binary subspace of dimension \(16w\) through all rounds, where \(w\) is the word size. - Both version of \textbf{WChain} message expansions preserve invariant sets and admit schedules with periods one, three, and six through all prescribed rounds and final whitening. - A cyclic shift of eight binary coordinates describes \textbf{Cuishen}'s message expansion on 256 register values throughout all 64 rounds. For fixed initial chaining and counter registers, the XOR differences between round keys have periods dividing eight.

The stated evaluation budgets for \textbf{CHIME-512} and \textbf{CHAMP} give success probabilities greater than \(0.39\). \keywords{Hash functions \and Cryptanalysis \and Collision attacks \and Invariant subspaces \and Message expansion}
Expand

Additional news items may be found on the IACR news page.