# Hamsi

## 1 The algorithm

## 2 Cryptanalysis

We distinguish between two cases: results on the complete hash function, and results on underlying building blocks.

A description of the tables is given here.

Recommended security parameters: (3,6) P,Pf rounds (n=224,256); (6,12) P,Pf rounds (n=384,512).

### 2.1 Hash function

Here we list results on the actual hash function. The only allowed modification is to change the security parameter.

 Type of Analysis Hash Function Part Hash Size (n) Parameters/Variants Compression Function Calls Memory Requirements Reference 2nd-preimage hash function 256 (3,6) 2251.3 ? Fuhr

### 2.2 Building blocks

Here we list results on underlying building blocks, and the hash function modified by other means than the security parameter.

Note that these results assume more direct control or access over some internal variables (aka. free-start, pseudo, compression function, block cipher, or permutation attacks).

 Type of Analysis Hash Function Part Hash Size (n) Parameters/Variants Compression Function Calls Memory Requirements Reference distinguisher output transformation 256 6 rounds 210 - Boura,Canteaut semi-free-start near-collisions compression function 256 2 rounds example - Turan,Uyan observations hash function all Gligoroski distinguisher output transformation 224, 256 6 rounds 2124.3 Aumasson et al. distinguisher permutation 224, 256 6 rounds 228 Aumasson et al. free-start near-collision compression function 224, 256 3 rounds 226 Aumasson et al. non-randomness compression function 224, 256 5 rounds Aumasson free-start near-collision compression function 224, 256 3 rounds 221 Nikolic distinguisher compression function 224, 256 6 rounds 227 Aumasson,Meier distinguisher compression function 384, 512 12 rounds 2729 Aumasson,Meier free-start near-collision compression function 224, 256 3 rounds 25 Wang,Wang,Jia,Wang free-start near-collision compression function 224, 256 4 rounds 232 Wang,Wang,Jia,Wang free-start near-collision compression function 224, 256 5 rounds 2125 Wang,Wang,Jia,Wang message-recovery compression function 224, 256 3 rounds 210.48 Calik,Turan pseudo-2nd-preimage hash function 256 (3,6) rounds 2254.25 Calik,Turan

