How to Abuse and Fix Authenticated Encryption Without Key Commitment
Ange Albertini, Thai Duong, Shay Gueron, Stefan Kölbl, Atul Luykx, Sophie Schmieg
摘要
Authenticated encryption (AE) is used in a wide variety of applications, potentially in settings for which it was not originally designed. Recent research tries to understand what happens when AE is not used as prescribed by its designers. A question given relatively little attention is whether an AE scheme guarantees "key commitment": ciphertext should only decrypt to a valid plaintext under the key used to generate the ciphertext. Generally, AE schemes do not guarantee key commitment as it is not part of AE's design goal. Nevertheless, one would not expect this seemingly obscure property to have much impact on the security of actual products. In reality, however, products do rely on key commitment. We discuss three recent applications where missing key commitment is exploitable in practice. We provide proof-of-concept attacks via a tool that constructs AES-GCM ciphertext which can be decrypted to two plaintexts valid under a wide variety of file formats, such as PDF, Windows executables, and DICOM. Finally we discuss two solutions to add key commitment to AE schemes which have not been analyzed in the literature: a generic approach that adds an explicit key commitment scheme to the AE scheme, and a simple fix which works for AE schemes like AES-GCM and ChaCha20Poly1305, but requires separate analysis for each scheme.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 被引用 54 次
- POPSTAR: Lightweight Threshold Reporting with Reduced LeakageHanjun Li, Sela Navot, Stefano TessaroUSENIX Security 2024 · 被引用 5 次
- A Concrete Treatment of Efficient Continuous Group Key Agreement via Multi-Recipient PKEsKeitaro Hashimoto, Shuichi Katsumata, Eamonn W. Postlethwaite, Thomas Prest 等CCS 2021 · 被引用 1 次
- Automated Analysis of Protocols that use Authenticated Encryption: How Subtle AEAD Differences can impact Protocol SecurityCas Cremers, Alexander Dax, Charlie Jacomme, Mang ZhaoUSENIX Security 2023
- MEGA: Malleable Encryption Goes AwryMatilda Backendal, Miro Haller, Kenneth G. PatersonS&P 2023
它引用的顶会 Paper3
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 被引用 57 次
- Automating the Development of Chosen Ciphertext AttacksGabrielle Beck, Maximilian Zinkus, Matthew GreenUSENIX Security 2020
- SHA-1 is a Shambles: First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of TrustGaëtan Leurent, Thomas PeyrinUSENIX Security 2020
相关 Paper
- A Robust Variant of ChaCha20-Poly1305Tim Beyne, Yu Long Chen, Michiel VerbauwhedeCRYPTO 2026 · 被引用 1 次
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 被引用 11 次
- Committing Authenticated Encryption: Generic Transforms with Hash FunctionsShan Chen, Vukasin KaradzicEUROCRYPT 2025 · 被引用 3 次
- Generic Committing Attacks - Zero-Padded Ascon is Less Secure than ExpectedNilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki 等CRYPTO 2026
- The Security of ChaCha20-Poly1305 in the Multi-User SettingJean Paul Degabriele, Jérôme Govinden, Felix Günther, Kenneth G. PatersonCCS 2021 · 被引用 23 次
