USENIX Security2022Top-tier venue
How to Abuse and Fix Authenticated Encryption Without Key Commitment
Ange Albertini, Thai Duong, Shay Gueron, Stefan Kölbl, Atul Luykx, Sophie Schmieg
Abstract
Authenticated encryption (AE) is used in a wide variety of applications, potentially in settings for which it was not originally designed. Recent research tries to understand what happens when AE is not used as prescribed by its designers. A question given relatively little attention is whether an AE scheme guarantees "key commitment": ciphertext should only decrypt to a valid plaintext under the key used to generate the ciphertext. Generally, AE schemes do not guarantee key commitment as it is not part of AE's design goal. Nevertheless, one would not expect this seemingly obscure property to have much impact on the security of actual products. In reality, however, products do rely on key commitment. We discuss three recent applications where missing key commitment is exploitable in practice. We provide proof-of-concept attacks via a tool that constructs AES-GCM ciphertext which can be decrypted to two plaintexts valid under a wide variety of file formats, such as PDF, Windows executables, and DICOM. Finally we discuss two solutions to add key commitment to AE schemes which have not been analyzed in the literature: a generic approach that adds an explicit key commitment scheme to the AE scheme, and a simple fix which works for AE schemes like AES-GCM and ChaCha20Poly1305, but requires separate analysis for each scheme.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 12cc8cb8-d589-43c3-a6ef-c9c74528c0b5Cited by top-tier papers7
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 54 citations
- POPSTAR: Lightweight Threshold Reporting with Reduced LeakageHanjun Li, Sela Navot, Stefano TessaroUSENIX Security 2024 · 5 citations
- A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsKeitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest et al.CCS 2021 · 1 citation
- Automated Analysis of Protocols that use Authenticated Encryption: How Subtle AEAD Differences can impact Protocol SecurityCas Cremers, Alexander Dax, Charlie Jacomme, Mang ZhaoUSENIX Security 2023
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
Builds on3
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 57 citations
- Automating the Development of Chosen Ciphertext AttacksGabrielle Beck, Maximilian Zinkus, Matthew GreenUSENIX Security 2020
- SHA-1 is a Shambles: First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of TrustGaëtan Leurent, Thomas PeyrinUSENIX Security 2020
Related papers
- A Robust Variant of ChaCha20-Poly1305Tim Beyne, Yu Long Chen, Michiel VerbauwhedeCRYPTO 2026 · 1 citation
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 11 citations
- Committing Authenticated Encryption: Generic Transforms with Hash FunctionsShan Chen, Vukasin KaradzicEUROCRYPT 2025 · 3 citations
- Generic Committing Attacks - Zero-Padded Ascon is Less Secure than ExpectedNilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki et al.CRYPTO 2026
- The Security of ChaCha20-Poly1305 in the Multi-User SettingJean Paul Degabriele, Jérôme Govinden, Felix Günther, Kenneth G. PatersonCCS 2021 · 23 citations
