Paper 2025/2017
Secure Onion Encryption and the Case of Counter Galois Onion
Abstract
The recently introduced Counter Galois Onion (CGO) is a new symmetric onion encryption scheme designed to replace the current one used by Tor, with integration in Tor’s Rust implementation Arti ongoing. Intuitively, CGO uses an updatable tweakable split-domain cipher as its building block, which provides it with the necessary non-malleability properties while attaining better performance than the alternative approach of realising it from a wide blockcipher (with full SPRP security). However, onion encryption as used in Tor with various functionality features and security trade-offs, is not that well-studied by the cryptographic community. As a result, the requirements of this important primitive which protects the privacy of millions of users on a daily basis, is not well understood and whether CGO fulfills all its security goals unclear. In this work, we initiate the study of real-world symmetric onion encryption by presenting a new security model capturing Tor’s leaky pipes functionality, associated data, and partial forward security, neither of which were covered previously. We then use this new security model to solidify the security claims of CGO in the forward direction by proving that if the underlying primitive is a suitably secure tweakable split-domain cipher, then CGO is a secure onion encryption scheme.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- TorOnion EncryptionTagging AttacksForward SecurityRPRP
- Contact author(s)
-
jeanpaul degabriele @ tii ae
alessandro melloni 29 @ gmail com
martijn @ simula no - History
- 2025-11-01: approved
- 2025-10-30: received
- See all versions
- Short URL
- https://ia.cr/2025/2017
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2017,
author = {Jean Paul Degabriele and Alessandro Melloni and Martijn Stam},
title = {Secure Onion Encryption and the Case of Counter Galois Onion},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2017},
year = {2025},
url = {https://eprint.iacr.org/2025/2017}
}