Mind the Composition: Birthday Bound Attacks on EWCDMD and SoKAC21
Mridul Nandi
摘要
In an early version of CRYPTO’17, Mennink and Neves pro- posed EWCDMD, a dual of EWCDM, and showed n-bit security, where n is the block size of the underlying block cipher. In CRYPTO’19, Chen et al. proposed permutation based design SoKAC21 and showed 2n/3- bit security, where n is the input size of the underlying permutation. In this paper we show birthday bound attacks on EWCDMD and SoKAC21, invalidating their security claims. Both attacks exploit an inherent com- position nature present in the constructions. Motivated by the above two attacks exploiting the composition nature, we consider some generic relevant composition based constructions of ideal primitives (possibly in the ideal permutation and random oracle model) and present birthday bound distinguishers for them. In particular, we demonstrate a birthday bound distinguisher against (1) a secret random permutation followed by a public random function and (2) composition of two secret random functions. Our distinguishers for SoKAC21 and EWCDMD are direct con- sequences of (1) and (2) respectively.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- How to Build a Short-Input Random Oracle from Public Random PermutationsRitam Bhaumik, Nilanjan Datta, Avijit Dutta, Ashwin Jha 等EUROCRYPT 2026
- Revisiting the Indifferentiability of the Sum of PermutationsAldo Gunsing, Ritam Bhaumik, Ashwin Jha, Bart Mennink 等CRYPTO 2023 · 被引用 10 次
- Combining Outputs of a Random Permutation: New Constructions and Tight Security Bounds by Fourier AnalysisItai DinurEUROCRYPT 2025 · 被引用 1 次
- Generic Attack on Duplex-Based AEAD Modes Using Random Function StatisticsHenri Gilbert, Rachelle Heim Boissier, Louiza Khati, Yann RotellaEUROCRYPT 2023 · 被引用 5 次
- Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW ParadigmAshwin Jha, Mustafa Khairallah, Mridul Nandi, Abishanka SahaEUROCRYPT 2024 · 被引用 7 次
