Paper 2025/2017

Secure Onion Encryption and the Case of Counter Galois Onion

Jean Paul Degabriele, Technology Innovation Institute
Alessandro Melloni, Simula UiB
Martijn Stam, Simula UiB
Abstract

The recently introduced Counter Galois Onion (CGO) is a new symmetric onion encryption scheme designed to replace the current one used by Tor, with integration in Tor’s Rust implementation Arti ongoing. Intuitively, CGO uses an updatable tweakable split-domain cipher as its building block, which provides it with the necessary non-malleability properties while attaining better performance than the alternative approach of realising it from a wide blockcipher (with full SPRP security). However, onion encryption as used in Tor with various functionality features and security trade-offs, is not that well-studied by the cryptographic community. As a result, the requirements of this important primitive which protects the privacy of millions of users on a daily basis, is not well understood and whether CGO fulfills all its security goals unclear. In this work, we initiate the study of real-world symmetric onion encryption by presenting a new security model capturing Tor’s leaky pipes functionality, associated data, and partial forward security, neither of which were covered previously. We then use this new security model to solidify the security claims of CGO in the forward direction by proving that if the underlying primitive is a suitably secure tweakable split-domain cipher, then CGO is a secure onion encryption scheme.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
TorOnion EncryptionTagging AttacksForward SecurityRPRP
Contact author(s)
jeanpaul degabriele @ tii ae
alessandro melloni 29 @ gmail com
martijn @ simula no
History
2025-11-01: approved
2025-10-30: received
See all versions
Short URL
https://ia.cr/2025/2017
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2017,
      author = {Jean Paul Degabriele and Alessandro Melloni and Martijn Stam},
      title = {Secure Onion Encryption and the Case of Counter Galois Onion},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2017},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2017}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.