Anamorphic Resistant Encryption: the Good, the Bad and the Ugly
Davide Carnemolla, Dario Catalano, Emanuele Giunta, Francesco Migliaro
Abstract
Anamorphic encryption (AE), introduced by Persiano, Phan and Yung at Eurocrypt `22, allows to establish secure communication in scenarios where users might be forced to hand over their decryption keys to some hostile authority. Over the last few years, several works have improved our understanding of the primitive by proposing novel realizations, new security notions and studying inherent limitations. This work makes progress, mainly, on this last line of research. We show concrete realizations of public key encryption schemes that, provably, cannot be turned anamorphic. These were called Anamorphic Resistant Encryption (ARE, fort short) in a recent work of Dodis and Goldin. We also show that, under certain conditions, anamorphic encryption is equivalent to algorithm substitution attacks. This allows to positively reinterpret our AREs as PKE schemes provably resistant to subversion attacks. To the best of our knowledge, these seem to be the first IND-CPA secure schemes achieving subversion resistance without trust assumptions or non-black-box decomposition techniques. Our two AREs heavily rely, among other things, on a direct usage of extremely lossy functions: here the lossyness property is used in the constructions, rather than just in the proofs. The first construction is in the public parameters model and also requires iO. The second construction eliminates the need of both public parameters and iO, but is in the random oracle and relies on the novel concept of robust extremely lossy functions with group structure, a primitive that we define and (show how to) realize in this paper.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei et al.USENIX Security 2026 · 1 citation
- Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLSHien Chu, Alessandro Corsi, Paul RöslerUSENIX Security 2026
Related papers
- The Malice of ELFs: Practical Anamorphic-Resistant Encryption Without Random OraclesGennaro Avitabile, Vincenzo Botta, Emanuele Giunta, Marcin Mielniczuk et al.EUROCRYPT 2026 · 3 citations
- Limits of Black-Box Anamorphic EncryptionDario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2024 · 14 citations
- Generic Anamorphic Encryption, Revisited: New Limitations and ConstructionsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2025 · 10 citations
- Fully Asymmetric Anamorphic Homomorphic Encryption from LWEAmit Deo, Benoît LibertEUROCRYPT 2026 · 1 citation
- Anamorphic Encryption: New Constructions and Homomorphic RealizationsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2024 · 19 citations
