Generic Anamorphic Encryption, Revisited: New Limitations and Constructions
Dario Catalano, Emanuele Giunta, Francesco Migliaro
Abstract
The notion of Anamorphic Encryption (Persiano et al. Eurocrypt 2022) aims at establishing private communication against an adversary who can access secret decryption keys and influence the chosen messages. Persiano et al. gave a simple, black-box, rejection sampling-based technique to send anamorphic bits using any IND-CPA secure scheme as underlying PKE.
In this paper however we provide evidence that their solution is not as general as claimed: indeed there exists a (contrived yet secure) PKE which lead to insecure anamorphic instantiations. Actually, our result implies that such stateless black-box realizations of AE are impossible to achieve, unless weaker notions are targeted or extra assumptions are made on the PKE. Even worse, this holds true even if one resorts to powerful non-black-box techniques, such as NIZKs, or garbling.
From a constructive perspective, we shed light those required assumptions. Specifically, we show that one could bypass (to some extent) our impossibility by either considering a weaker (but meaningful) notion of AE or by assuming the underlying PKE to (always) produce high min-entropy ciphertexts.
Finally, we prove that, for the case of Fully-Asymmetric AE, can actually be used to overcome existing impossibility barriers. We show how to use to build Fully-Asymmetric AE (with small anamorphic message space) generically from any IND-CPA secure PKE with sufficiently high min-entropy ciphertexts. Put together our results provide a clearer picture of what black-box constructions can and cannot achieve.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Crypto Wars in Secure Messaging: Covert Channels in Signal Despite Leaked KeysRosario Giustolisi, Gabriele Lenzini, Chuanwei Lin, Mohammadamin Rakeei et al.USENIX Security 2026 · 1 citation
- Anamorphic Messaging: Analyzing the Double Ratchet, Triple Ratchet, PQ3, and MLSHien Chu, Alessandro Corsi, Paul RöslerUSENIX Security 2026
Related papers
- Limits of Black-Box Anamorphic EncryptionDario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2024 · 14 citations
- Anamorphic Resistant Encryption: the Good, the Bad and the UglyDavide Carnemolla, Dario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2025 · 6 citations
- The Malice of ELFs: Practical Anamorphic-Resistant Encryption Without Random OraclesGennaro Avitabile, Vincenzo Botta, Emanuele Giunta, Marcin Mielniczuk et al.EUROCRYPT 2026 · 3 citations
- Anamorphic Encryption: New Constructions and Homomorphic RealizationsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2024 · 19 citations
- Fully Asymmetric Anamorphic Homomorphic Encryption from LWEAmit Deo, Benoît LibertEUROCRYPT 2026 · 1 citation
