USENIX Security2021Top-tier venue
Partitioning Oracle Attacks
Julia Len, Paul Grubbs, Thomas Ristenpart
Abstract
In this paper we introduce partitioning oracles, a new class of decryption error oracles which, conceptually, take a ciphertext as input and output whether the decryption key belongs to some known subset of keys. Partitioning oracles can arise when encryption schemes are not committing with respect to their keys. We detail adaptive chosen ciphertext attacks that exploit partitioning oracles to efficiently recover passwords and de-anonymize anonymous communications. The attacks utilize efficient key multi-collision algorithms -a cryptanalytic goal that we define -against widely used authenticated encryption with associated data (AEAD) schemes, including AES-GCM, XSalsa20/Poly1305, and ChaCha20/Poly1305. We build a practical partitioning oracle attack that quickly recovers passwords from Shadowsocks proxy servers. We also survey early implementations of the OPAQUE protocol for password-based key exchange, and show how many could be vulnerable to partitioning oracle attacks due to incorrectly using non-committing AEAD. Our results suggest that the community should standardize and make widely available key-committing AEAD to avoid such vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e50fa650-983d-4782-8221-a272c053f9f5Cited by top-tier papers7
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 54 citations
- Anonymous, Robust Post-quantum Public Key EncryptionPaul Grubbs, Varun Maram, Kenneth G. PatersonEUROCRYPT 2022 · 36 citations
- Automated Analysis of Protocols that use Authenticated Encryption: How Subtle AEAD Differences can impact Protocol SecurityCas Cremers, Alexander Dax, Charlie Jacomme, Mang ZhaoUSENIX Security 2023
- How to Abuse and Fix Authenticated Encryption Without Key CommitmentAnge Albertini, Thai Duong, Shay Gueron, Stefan Kölbl et al.USENIX Security 2022
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
Builds on6
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 146 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
- Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessageChristina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers et al.USENIX Security 2016 · 62 citations
- The Dangers of Key Reuse: Practical Attacks on IPsec IKEDennis Felsch, Martin Grothe, Jörg Schwenk, Adam Czubak et al.USENIX Security 2018 · 41 citations
- Pseudo Constant Time Implementations of TLS Are Only Pseudo SecureEyal Ronen, Kenneth G. Paterson, Adi ShamirCCS 2018 · 34 citations
Related papers
- A Robust Variant of ChaCha20-Poly1305Tim Beyne, Yu Long Chen, Michiel VerbauwhedeCRYPTO 2026 · 1 citation
- Generic Committing Attacks - Zero-Padded Ascon is Less Secure than ExpectedNilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki et al.CRYPTO 2026
- The Security of ChaCha20-Poly1305 in the Multi-User SettingJean Paul Degabriele, Jérôme Govinden, Felix Günther, Kenneth G. PatersonCCS 2021 · 23 citations
- Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and MoreSanketh Menda, Julia Len, Paul Grubbs, Thomas RistenpartEUROCRYPT 2023 · 17 citations
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 11 citations
