Anamorphic Encryption, Revisited
Fabio Banfi, Konstantin Gegier, Martin Hirt, Ueli Maurer, Guilherme Rito
Abstract
An anamorphic encryption scheme allows two parties who share a so-called double key to embed covert messages in ciphertexts of an established PKE scheme. This protects against a dictator that can force the receiver to reveal the secret keys for the PKE scheme, but who is oblivious about the existence of the double key. We identify two limitations of the original model by Persiano, Phan, and Yung (EUROCRYPT 2022). First, in their definition a double key can only be generated once, together with a key-pair. This has the drawback that a receiver who wants to use the anamorphic mode after a dictator comes to power, needs to deploy a new key-pair, a potentially suspicious act. Second, a receiver cannot distinguish whether or not a ciphertext contains a covert message.
In this work we propose a new model that overcomes these limitations. First, we allow to associate multiple double keys to a key-pair, after its deployment. This also enables deniability in case the double key only depends on the public key. Second, we propose a natural robustness notion, which guarantees that anamorphically decrypting a regularly encrypted message results in a special symbol indicating that no covert message is contained, which also eliminates certain attacks.
Finally, to instantiate our new, stronger definition of anamorphic encryption, we provide generic and concrete constructions. Concretely, we show that ElGamal and Cramer-Shoup satisfy a new condition, selective randomness recoverability, which enables robust anamorphic extensions, and we also provide a robust anamorphic extension for RSA-OAEP.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7c157b83-afa2-48f2-90e5-a05a95bde72eCited by top-tier papers2
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei et al.USENIX Security 2026 · 1 citation
- Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLSHien Chu, Alessandro Corsi, Paul RöslerUSENIX Security 2026
Builds on5
- Generic Semantic Security against a Kleptographic AdversaryAlexander Russell, Qiang Tang, Moti Yung, Hong-Sheng ZhouCCS 2017 · 71 citations
- Anamorphic Encryption: Private Communication Against a DictatorGiuseppe Persiano, Duong Hieu Phan, Moti YungEUROCRYPT 2022 · 45 citations
- Anamorphic Signatures: Secrecy from a Dictator Who Only Permits Authentication!Miroslaw Kutylowski, Giuseppe Persiano, Duong Hieu Phan, Moti Yung et al.CRYPTO 2023 · 31 citations
- Anamorphic Encryption: New Constructions and Homomorphic RealizationsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2024 · 19 citations
- Abuse Resistant Law Enforcement Access SystemsMatthew Green, Gabriel Kaptchuk, Gijs Van LaerEUROCRYPT 2021 · 17 citations
Related papers
- A Unified Treatment of Anamorphic EncryptionWonseok Choi, Daniel Collins, Xiangyu Liu, Roy Stracovsky et al.CRYPTO 2026
- Limits of Black-Box Anamorphic EncryptionDario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2024 · 14 citations
- The Malice of ELFs: Practical Anamorphic-Resistant Encryption Without Random OraclesGennaro Avitabile, Vincenzo Botta, Emanuele Giunta, Marcin Mielniczuk et al.EUROCRYPT 2026 · 3 citations
- Public-Key Anamorphism in (CCA-Secure) Public-Key Encryption and BeyondGiuseppe Persiano, Duong Hieu Phan, Moti YungCRYPTO 2024 · 14 citations
- Fully Asymmetric Anamorphic Homomorphic Encryption from LWEAmit Deo, Benoît LibertEUROCRYPT 2026 · 1 citation
