Key Committing Security of HCTR2, Revisited
Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito, Yu Sasaki, Takeshi Sugawara
Abstract
This paper presents improved attacks and proofs for the key committing security of EtE-HCTR2, a robust authenticated encryption scheme constructed from HCTR2 and the Encode-then-Encipher (EtE) framework, in light of the ongoing standardization effort of cryptographic accordions by NIST. We improve attacks on the instantiations with two common encodings, where zeros are either appended or prepended to the message, namely EtE_A-HCTR2 and EtE_P-HCTR2. Compared with the state-of-the-art attack by Chen et al. in ToSC 2023(4), our EtE_A-HCTR2 attack reduces the complexity from to for an -bit block cipher and -bit zero padding, which degrades EtE_A-HCTR2's security below the birthday bound. Meanwhile, our EtE_P-HCTR2 attack reduces the complexity from to , which is tight with our new security proof. We verify these computationally-bounded attacks by experimentally generating concrete vectors for both EtE_A-HCTR2 with and EtE_P-HCTR2 with , each instantiated with , in less than 15 minutes.
We consider yet another padding scheme that appends zeros to the first message block, namely EtE_S-HCTR2, and prove that it has a tight committing security bound of by avoiding the issue in EtE_A-HCTR2.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9d2bd57a-e119-421e-83c3-9b18faba1d92Related papers
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 11 citations
- Generic Committing Attacks - Zero-Padded Ascon is Less Secure than ExpectedNilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki et al.CRYPTO 2026
- How to Abuse and Fix Authenticated Encryption Without Key CommitmentAnge Albertini, Thai Duong, Shay Gueron, Stefan Kölbl et al.USENIX Security 2022
- Committing Authenticated Encryption: Generic Transforms with Hash FunctionsShan Chen, Vukasin KaradzicEUROCRYPT 2025 · 3 citations
- Towards Optimally Secure Deterministic Authenticated Encryption SchemesYu Long Chen, Avijit Dutta, Ashwin Jha, Mridul NandiEUROCRYPT 2025 · 2 citations
