Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW Paradigm
Ashwin Jha, Mustafa Khairallah, Mridul Nandi, Abishanka Saha
Abstract
Liskov, Rivest and Wagner laid the theoretical foundations for tweakable block ciphers (TBC). In a seminal paper, they proposed two (up to) birthday-bound secure design strategies --- LRW1 and LRW2 --- to convert any block cipher into a TBC. Several of the follow-up works consider cascading of LRW-type TBCs to construct beyond-the-birthday bound (BBB) secure TBCs. Landecker et al. demonstrated that just two-round cascading of LRW2 can already give a BBB security. Bao et al. undertook a similar exercise in context of LRW1 with TNT --- a three-round cascading of LRW1 --- that has been shown to achieve BBB security as well. In this paper, we present a CCA distinguisher on TNT that achieves a non-negligible advantage with queries, directly contradicting the security claims made by the designers. We provide a rigorous and complete advantage calculation coupled with experimental verification that further support our claim. Next, we provide new and simple proofs of birthday-bound CCA security for both TNT and its single-key variant, which confirm the tightness of our attack. Furthering on to a more positive note, we show that adding just one more block cipher call, referred as 4-LRW1, does not just re-establish the BBB security, but also amplifies it up to queries. As a side-effect of this endeavour, we propose a new abstraction of the cascaded LRW-design philosophy, referred to as the LRW+ paradigm, comprising two block cipher calls sandwiched between a pair of tweakable universal hashes. This helps us to provide a modular proof covering all cascaded LRW constructions with at least rounds, including 4-LRW1, and its more established relative, the well-known CLRW2, or more aptly, 2-LRW2.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9c7c32e3-6b86-4b21-8fcf-e5497df78b46Related papers
- Tweakable Permutation-Based Luby-Rackoff ConstructionsBishwajit Chakraborty, Abishanka SahaCRYPTO 2025
- TNT: How to Tweak a Block CipherZhenzhen Bao, Chun Guo, Jian Guo, Ling SongEUROCRYPT 2020 · 20 citations
- How to Recover the Full Plaintext of XCBPeng Wang, Shuping Mao, Ruozhou Xu, Jiwu Jing et al.CRYPTO 2025 · 3 citations
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 4 citations
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 29 citations
