Mario Lamberger, Florian Mendel: Higher-Order Differential Attack on Reduced SHA-256. IACR Cryptol. ePrint Arch. 2011: 37 (2011)