Lune

CRYPTO2026顶会

Key Committing Security of HCTR2, Revisited

Donghoon Chang, Yu Long Chen, Yukihito Hiraga, Kazuhiko Minematsu, Nicky Mouha, Yusuke Naito, Yu Sasaki, Takeshi Sugawara

2026年份

摘要

This paper presents improved attacks and proofs for the key committing security of EtE-HCTR2, a robust authenticated encryption scheme constructed from HCTR2 and the Encode-then-Encipher (EtE) framework, in light of the ongoing standardization effort of cryptographic accordions by NIST. We improve attacks on the instantiations with two common encodings, where zeros are either appended or prepended to the message, namely EtE_A-HCTR2 and EtE_P-HCTR2. Compared with the state-of-the-art attack by Chen et al. in ToSC 2023(4), our EtE_A-HCTR2 attack reduces the complexity from O(2τ/2)O(2^{\tau/2}) to O(2max⁡{τ/3,τ−n})O(2^{\max\{\tau/3, \tau-n\}}) for an nn-bit block cipher and τ\tau-bit zero padding, which degrades EtE_A-HCTR2's security below the birthday bound. Meanwhile, our EtE_P-HCTR2 attack reduces the complexity from O(2min⁡{n/2,τ})O(2^{\min \{n/2, \tau\}}) to O(2τ/2)O(2^{\tau/2}), which is tight with our new security proof. We verify these computationally-bounded attacks by experimentally generating concrete vectors for both EtE_A-HCTR2 with τ=96\tau=96 and EtE_P-HCTR2 with τ=64\tau=64, each instantiated with n=128n=128, in less than 15 minutes.
We consider yet another padding scheme that appends zeros to the first message block, namely EtE_S-HCTR2, and prove that it has a tight committing security bound of O(2τ/2)O(2^{\tau/2}) by avoiding the issue in EtE_A-HCTR2.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get 9d2bd57a-e119-421e-83c3-9b18faba1d92

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖