Matusiewicz, KrystianPieprzyk, JosefPramstaller, NorbertRechberger, ChristianRijmen, VincentWulf, ChristopherLucks, StefanYau, Po-Wah2019-08-262019-08-2620053-88579-403-9https://dl.gi.de/handle/20.500.12116/24844In this paper we analyse the role of some of the building blocks of SHA-256. We show that the disturbance-correction strategy is applicable to the SHA-256 architecture and we prove that functions Σ, σ are vital for the security of SHA-256 by showing that for a variant without them it is possible to find collisions with complexity 264 hash operations. As a step towards an analysis of the full function, we present the results of our experiments on Hamming weights of expanded messages for different variants of the message expansion and show that there exist low-weight expanded messages for XOR-linearised variants.enAnalysis of simplified variants of SHA-256*Text/Conference Paper1617-5468