Paper 2024/598

AE Robustness as Indistinguishable Decryption Leakage amid Multiple Failure Conditions

Ganyuan Cao, École Polytechnique Fédérale de Lausanne
Abstract

Robustness has emerged as a critical criterion for authenticated encryption, alongside confidentiality and integrity. In this study, we revisit AEAD robustness by focusing on descriptive errors when multiple failure conditions exist. We introduce new notion, IND-CCLA and IND-sf-CCLA, that expands on classical security notions defined for AEAD by incorporating the indistinguishability of decryption leakage including text-based values and descriptive errors. We highlight that simply outputting a single error message when decryption fails is insufficient to guarantee robustness, as leakage can undermine this approach. We examine error flags used when validating a ciphertext during the decryption process, and investigate whether it is possible to merge multiple error flags into one to mitigate this security risk. This helps to prevent the resulted leakage from giving adversaries additional advantage in future attacks, particularly when parts of the failure-checking mechanism have implementation flaws or disabled by an adversary through implementation-level attacks. We provide a concrete proof of the robustness of Encode-then-Encipher ($\textsf{EtE}$) paradigm using our notions, demonstrating its capability to validate multiple failure conditions using a single error flag. We briefly revisit generic compositions for AE to show the practical relevance of our notions. We further present a transformation from our notion to a simulatable one, supporting future research on composable security regarding decryption leakage.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
AE RobustnessDecryption LeakageIND-CCLAError ObfuscationSecurity Proof
Contact author(s)
ganyuan cao @ epfl ch
History
2024-06-21: last of 9 revisions
2024-04-17: received
See all versions
Short URL
https://ia.cr/2024/598
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/598,
      author = {Ganyuan Cao},
      title = {{AE} Robustness as Indistinguishable Decryption Leakage amid Multiple Failure Conditions},
      howpublished = {Cryptology ePrint Archive, Paper 2024/598},
      year = {2024},
      note = {\url{https://eprint.iacr.org/2024/598}},
      url = {https://eprint.iacr.org/2024/598}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.