SearcharxivSearch

arXiv · 2511.15842

Preimages for Z\'emor's Cayley hash function

Abstract

In 1991, Z\'emor proposed a hash function which provides data security using the difficulty of writing a given matrix as a product of generator matrices. Tillich and Z\'emor subsequently provided an algorithm finding short collisions for this hash function. We extend this collision attack to a stronger preimage attack, under the assumption that we can factor large integers efficiently. The Euclidean algorithm will factor a $2\times 2$ matrix with non-negative integer entries and determinant $1$. This factorization is short if the matrix entries are all roughly the same size. Therefore, to factor a matrix we need only find an integer matrix with the listed properties which is congruent to the target matrix modulo $p$; finding such an integer matrix is equivalent to solving a Diophantine equation. We give an algorithm to solve this equation.

Explore related subjects

Keep this discovery

BibTeXRIS

Eilidh McKemmie, Amol Srivastava. 2025-11-19. Preimages for Z\'emor's Cayley hash function. https://arxiv.org/abs/2511.15842

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Reversibility and its asymptotic counting in Picard group

We investigate reversible elements in the Picard modular group $\mathrm{PSL}(2,\mathbb{Z}[i])$. We show that reversibility coincides with strong reversibility for Kleinian groups, in particular for the Picard group. We classify reversible elements in the Picard group and characterize loxodromic reversible elements up to conjugacy. We prove that each such conjugacy class contains exactly eight special representatives. We also obtain asymptotic estimates for the number of reversible conjugacy classes with bounded trace.

math.GR

Conjugator length in finitely generated groups

We describe all functions $\mathbb{N}\rightarrow \mathbb{N}$ that can be realized, up to the standard equivalence, as conjugator length functions of finitely generated groups. Furthermore, we show that any two increasing functions $f,g\colon \mathbb N\to \mathbb N$ can be simultaneously realized as conjugator length functions of finitely generated, commensurable (in particular, quasi-isometric) groups.

math.GR

The spectrum of conjugator length functions

A recent program tries to find which functions appear as conjugator length functions. In this note, we show that any (computable) increasing function larger than $n$ appears as $\mathrm{Cl}_G$ for some finitely generated (recursively presented) group. On the other hand, we demonstrate that either $\mathrm{Cl}_G$ must be constant or $\mathrm{Cl}_G(n)\succ n$. Combining these, we obtain a complete description of which functions appear as conjugator length functions of finitely generated groups.

math.GR