Limits of Black-Box Anamorphic Encryption
Dario Catalano, Emanuele Giunta, Francesco Migliaro
Abstract
(Receiver) Anamorphic encryption, introduced by Persiano at Eurocrypt 2022, considers the question of achieving private communication in a world where secret decryption keys are under the control of a dictator. The challenge here is to be able to establish a secret communication channel to exchange covert (i.e. anamorphic) messages on top of some already deployed public key encryption scheme.
Over the last few years several works addressed this challenge by showing new constructions, refined notions and extensions. Most of these constructions, however, are either ad hoc, in the sense that they build upon specific properties of the underlying PKE, or impose severe restrictions on the size of the underlying anamorphic message space.
In this paper we consider the question of whether it is possible to have realizations of the primitive that are both generic and allow for large anamorphic message spaces. We give strong indications that, unfortunately, this is not the case.
Our first result shows that of the primitive, i.e. any realization that accesses the underlying PKE only via oracle calls, have an anamorphic message space of size at most ( security parameter).
Even worse, if one aims at stronger variants of the primitive (and, specifically, the notion of asymmetric anamorphic encryption, recently proposed by Catalano ) we show that such black-box realizations are plainly impossible, i.e. no matter how small the anamorphic message space is.
Finally, we show that our impossibility results are rather tight: indeed, by making more specific assumptions on the underlying PKE, it becomes possible to build generic AE where the anamorphic message space is of size .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f79c4ec5-be3c-4b70-b44b-f2d634270fd7Cited by top-tier papers1
Ask how each one uses itRelated papers
- Generic Anamorphic Encryption, Revisited: New Limitations and ConstructionsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2025 · 10 citations
- Anamorphic Encryption: New Constructions and Homomorphic RealizationsDario Catalano, Emanuele Giunta, Francesco MigliaroEUROCRYPT 2024 · 19 citations
- The Malice of ELFs: Practical Anamorphic-Resistant Encryption Without Random OraclesGennaro Avitabile, Vincenzo Botta, Emanuele Giunta, Marcin Mielniczuk et al.EUROCRYPT 2026 · 3 citations
- A Unified Treatment of Anamorphic EncryptionWonseok Choi, Daniel Collins, Xiangyu Liu, Roy Stracovsky et al.CRYPTO 2026
- Anamorphic Resistant Encryption: the Good, the Bad and the UglyDavide Carnemolla, Dario Catalano, Emanuele Giunta, Francesco MigliaroCRYPTO 2025 · 6 citations
