Generic Attack on Duplex-Based AEAD Modes Using Random Function Statistics
Henri Gilbert, Rachelle Heim Boissier, Louiza Khati, Yann Rotella
摘要
. Duplex-based authenticated encryption modes with a sufficiently large key length are proven to be secure up to the birthday bound 2 c 2 , where c is the capacity. However this bound is not known to be tight and the complexity of the best known generic attack, which is based on multicollisions, is much larger: it reaches 2 c α where α represents a small security loss factor. There is thus an uncertainty on the true extent of security beyond the bound 2 c 2 provided by such constructions. In this paper, we describe a new generic attack against several duplex-based AEAD modes. Our attack leverages random functions statistics and produces a forgery in time complexity O (2 3 c 4 ) using negligible memory and no encryption queries. Furthermore, for some duplex-based modes, our attack recovers the secret key with a negligible amount of additional computations. Most notably, our attack breaks a security claim made by the designers of the NIST lightweight competition candidate Xoodyak . This attack is a step further towards determining the exact security provided by duplex-based constructions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 被引用 4 次
- XOCB: Beyond-Birthday-Bound Secure Authenticated Encryption Mode with Rate-One ComputationZhenzhen Bao, Seongha Hwang, Akiko Inoue, ByeongHak Lee 等EUROCRYPT 2023 · 被引用 4 次
- Power Side-Channel Vulnerability Assessment of Lightweight Cryptographic Scheme, XOODYAKAnupam Golder, Debayan Das, Santosh Ghosh, Avinash Varna 等DAC 2023 · 被引用 3 次
- Tight Preimage Resistance of the Sponge ConstructionCharlotte Lefevre, Bart MenninkCRYPTO 2022 · 被引用 15 次
- Generic Committing Attacks - Zero-Padded Ascon is Less Secure than ExpectedNilanjan Datta, Hrithik Nandi, Soumit Pal, Yu Sasaki 等CRYPTO 2026
