The Malice of ELFs: Practical Anamorphic-Resistant Encryption Without Random Oracles
Gennaro Avitabile, Vincenzo Botta, Emanuele Giunta, Marcin Mielniczuk, Francesco Migliaro
Abstract
The concept of Anamorphic Encryption (Persiano, Phan, and Yung, EUROCRYPT'22), aims to enable private communication in settings where the usage of encryption is heavily controlled by a central authority (henceforth called the dictator) who can obtain users' secret keys. Since then, various works have improved our understanding of AE in several aspects, including its limitations. In this regard, two recent works at CRYPTO'25 constructed various Anamorphic-Resistant Encryption (ARE) schemes, i.e., schemes admitting at most bits of covert communication.
However, those results are still unsatisfactory, each coming with at least one of the following issues: (1) use of cryptographic heavy hammers such as indistinguishability obfuscation (iO); (2) abuse of the original definition to define overly powerful dictators; (3) reliance on the Random Oracle Model (ROM). In particular, proofs in the ROM are controversial as they fail to account for anamorphic schemes making non-black-box usage of the hash function used to instantiate the Random Oracle.
In this work, we overcome all of these limitations. First, we describe an anamorphic-resistant encryption scheme approaching practicality by relying only on public-key encryption and Extremely Lossy Functions (ELFs), both known from the (exponential) DDH assumption. Moreover, assuming Fully Unique NIZKs (known from iO), we provide another construction, which we later use to realize the first ARE; that is, a scheme that achieves the strongest level of anamorphic resistance against each of the possible levels of anamorphic security.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3d7aa327-930b-4413-8dbd-51ab7d727c85Cited by top-tier papers2
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei et al.USENIX Security 2026 · 1 citation
- Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLSHien Chu, Alessandro Corsi, Paul RöslerUSENIX Security 2026
Related papers
- Anamorphic Resistant Encryption: the Good, the Bad and the UglyDavide Carnemolla, Dario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2025 · 6 citations
- Limits of Black-Box Anamorphic EncryptionDario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2024 · 14 citations
- Generic Anamorphic Encryption, Revisited: New Limitations and ConstructionsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2025 · 10 citations
- Anamorphic Encryption: New Constructions and Homomorphic RealizationsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2024 · 19 citations
- A Unified Treatment of Anamorphic EncryptionWonseok Choi, Daniel Collins, Xiangyu Liu, Roy Stracovsky et al.CRYPTO 2026
