Mind the Composition: Birthday Bound Attacks on EWCDMD and SoKAC21
Mridul Nandi
Abstract
In an early version of CRYPTO’17, Mennink and Neves pro- posed EWCDMD, a dual of EWCDM, and showed n-bit security, where n is the block size of the underlying block cipher. In CRYPTO’19, Chen et al. proposed permutation based design SoKAC21 and showed 2n/3- bit security, where n is the input size of the underlying permutation. In this paper we show birthday bound attacks on EWCDMD and SoKAC21, invalidating their security claims. Both attacks exploit an inherent com- position nature present in the constructions. Motivated by the above two attacks exploiting the composition nature, we consider some generic relevant composition based constructions of ideal primitives (possibly in the ideal permutation and random oracle model) and present birthday bound distinguishers for them. In particular, we demonstrate a birthday bound distinguisher against (1) a secret random permutation followed by a public random function and (2) composition of two secret random functions. Our distinguishers for SoKAC21 and EWCDMD are direct con- sequences of (1) and (2) respectively.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3359ef8a-c8aa-444e-98d1-d40f2cfa8574Related papers
- How to Build a Short-Input Random Oracle from Public Random PermutationsRitam Bhaumik, Nilanjan Datta, Avijit Dutta, Ashwin Jha et al.EUROCRYPT 2026
- Revisiting the Indifferentiability of the Sum of PermutationsAldo Gunsing, Ritam Bhaumik, Ashwin Jha, Bart Mennink et al.CRYPTO 2023 · 10 citations
- Combining Outputs of a Random Permutation: New Constructions and Tight Security Bounds by Fourier AnalysisItai DinurEUROCRYPT 2025 · 1 citation
- Generic Attack on Duplex-Based AEAD Modes Using Random Function StatisticsHenri Gilbert, Rachelle Heim Boissier, Louiza Khati, Yann RotellaEUROCRYPT 2023 · 5 citations
- Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW ParadigmAshwin Jha, Mustafa Khairallah, Mridul Nandi, Abishanka SahaEUROCRYPT 2024 · 7 citations
