English

Preimages for Z\'emor's Cayley hash function

Group Theory 2025-11-21 v1

Abstract

In 1991, Z\'emor proposed a hash function which provides data security using the difficulty of writing a given matrix as a product of generator matrices. Tillich and Z\'emor subsequently provided an algorithm finding short collisions for this hash function. We extend this collision attack to a stronger preimage attack, under the assumption that we can factor large integers efficiently. The Euclidean algorithm will factor a 2×22\times 2 matrix with non-negative integer entries and determinant 11. This factorization is short if the matrix entries are all roughly the same size. Therefore, to factor a matrix we need only find an integer matrix with the listed properties which is congruent to the target matrix modulo pp; finding such an integer matrix is equivalent to solving a Diophantine equation. We give an algorithm to solve this equation.

Cite

@article{arxiv.2511.15842,
  title  = {Preimages for Z\'emor's Cayley hash function},
  author = {Eilidh McKemmie and Amol Srivastava},
  journal= {arXiv preprint arXiv:2511.15842},
  year   = {2025}
}

Comments

8 pages, 1 figure, comments welcome

R2 v1 2026-07-01T07:46:08.244Z