Generic Committing Attacks - Zero-Padded Ascon is Less Secure than Expected
Nilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki, Patrick Struck, Maximiliane Weishäupl
Abstract
We study generic committing attacks—where ciphertexts decrypt under more than one context, i.e., key, nonce, associated data—for sponge-based authenticated encryption. As our main contribution, we give three new committing attacks which outperform existing attacks. One of our attacks provides a counterexample showing that the previous proof for the committing security of Ascon-like schemes with zero-padding does not extend to all parameter choices: in case of 128-bit tags and 256-bit zero-padding, the existing analysis claims 192-bit security; our attack reduces this by 62 bits down to 130-bit. Our attacks are applicable to the standardized scheme Ascon. As a further contribution, we analyze existing attack strategies for a generic sponge construction with various design features such as key-blinding, zero-padding, and state-update-functions.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Key Committing Security of HCTR2, RevisitedDonghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu et al.CRYPTO 2026
- How to Abuse and Fix Authenticated Encryption Without Key CommitmentAnge Albertini, Thai Duong, Shay Gueron, Stefan Kölbl et al.USENIX Security 2022
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 54 citations
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 11 citations
- Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and MoreSanketh Menda, Julia Len, Paul Grubbs, Thomas RistenpartEUROCRYPT 2023 · 17 citations
