“Quantum Free-Start Collision Attacks on Double Block Length Hashing with Round-Reduced AES-256” (2021) IACR Transactions on Symmetric Cryptology, 2021(1), pp. 316–336. doi:10.46586/tosc.v2021.i1.316-336.