Reportshash-14 · Constant-time review

Laurus (hash-14)

CandidateLaurus
FamilySymmetric (permutation-based)
ArchiveLaurus.zip (SHA-256: 9499a772e532577f85902c0f631a95af8e2fb4bc308da6466c076debd63d1415)

hash-14-1: Laurus loses its function-domain separation at c=1024

SeverityMedium
Scopedesign
StatusConfirmed
AffectedSpecified generic Laurus[c,fid] interface at c=1024; the named XOF fixes c=512
DiscoveryModerate
ExploitationTrivial
CreditTsinghua Hash Lab cuihr26@mails.tsinghua.edu.cn
Date2026-09-22

Original source: CryptHashForum report

The specification uses fid=0 for hashing and fid=1 for XOF operation, placing the identifier only in the initial state. At c=1024, a message of 513 to 1024 bits causes one 512-bit absorption. That absorption omits the identifier from the permutation input and moves its difference into the first eight state words; finalization then discards exactly those words. The complete output is consequently independent of fid.

For example, the 768-bit all-zero message has identical 1024-bit outputs under Laurus[1024,0] and Laurus[1024,1]. This is a functional-domain separation failure in the normative generic interface, not a collision between distinct messages in a named fixed-output hash. The submitted Laurus-XOF wrapper fixes c=512, so it does not expose this particular pair through the uniform API.

Reproducing

Commands below run in a checkout of the ngcc-harness repository with the candidate built (see its README).

The target exposes the otherwise internal generic interface from the submitted source, checks the 768-bit equality, and checks a 512-bit negative control:

make -C hash-14 reproduce