Lune

EUROCRYPT2025顶会

Committing Authenticated Encryption: Generic Transforms with Hash Functions

Shan Chen, Vukasin Karadzic

2025年份
3被引次数
1顶会引用

摘要

Recent applications and attacks have highlighted the need for authenticated encryption (AE) schemes to achieve the so-called committing security beyond privacy and authenticity. As a result, several generic solutions have been proposed to transform a non-committing AE scheme to a committing one, for both basic unique-nonce security and advanced misuse-resistant (MR) security. We observe that all existing practical generic transforms are subject to at least one of the following limitations: (i) not committing to the entire encryption context, (ii) involving non-standard primitives, (iii) not being a black-box transform, (iv) providing limited committing security. Furthermore, so far, there has been no generic transform that can directly elevate a basic AE scheme to a committing AE scheme that offers MR security. Our work fills these gaps by developing black-box generic transforms that crucially rely on hash functions, which are well standardized and widely deployed.

First, we construct three basic transforms that combine AE with a single hash function, which we call HtAE,AEaH\mathsf{HtAE}, \mathsf{AEaH} and EtH\mathsf{EtH}. They all guarantee strong security, and EtH\mathsf{EtH} can be applied to both AE and basic privacy-only encryption schemes. Next, for MR security, we propose two advanced hash-based transforms that we call AEtH\mathsf{AEtH} and chaSIV\mathsf{chaSIV}. AEtH\mathsf{AEtH} is an MRAE-preserving transform that adds committing security to an MR-secure AE scheme. chaSIV\mathsf{chaSIV} is the first generic transform that can directly elevate basic AE to one with both committing and MR security; moreover, chaSIV\mathsf{chaSIV} also works with arbitrary privacy-only encryption schemes. Both of them feature a simple design and ensure strong security.

For performance evaluation, we compare our transforms to similar existing ones, both in theory and through practical implementations. The results show that our AEaH\mathsf{AEaH} achieves the highest practical efficiency among basic transforms, while AEtH\mathsf{AEtH} excels in MRAE-preserving transforms. Our MRAE-lifting transform chaSIV\mathsf{chaSIV} demonstrates comparable performance to MRAE-preserving ones and surpasses them for messages larger than approximately 360360 bytes; for longer messages, it even outperforms the benchmark, non-committing standardized AES-GCM-SIV\mathsf{AES}\text{-}\mathsf{GCM}\text{-}\mathsf{SIV}.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper1

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖