Lune

EUROCRYPT2023Top-tier venue

Generic Attack on Duplex-Based AEAD Modes Using Random Function Statistics

Henri Gilbert, Rachelle Heim Boissier, Louiza Khati, Yann Rotella

2023Year
5Citations
1Top-tier citations

Abstract

. Duplex-based authenticated encryption modes with a sufficiently large key length are proven to be secure up to the birthday bound 2 c 2 , where c is the capacity. However this bound is not known to be tight and the complexity of the best known generic attack, which is based on multicollisions, is much larger: it reaches 2 c α where α represents a small security loss factor. There is thus an uncertainty on the true extent of security beyond the bound 2 c 2 provided by such constructions. In this paper, we describe a new generic attack against several duplex-based AEAD modes. Our attack leverages random functions statistics and produces a forgery in time complexity O (2 3 c 4 ) using negligible memory and no encryption queries. Furthermore, for some duplex-based modes, our attack recovers the secret key with a negligible amount of additional computations. Most notably, our attack breaks a security claim made by the designers of the NIST lightweight competition candidate Xoodyak . This attack is a step further towards determining the exact security provided by duplex-based constructions.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers1

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines