Paper 2025/1480

SoK: Kleptographic Attacks

Ting-Yun Yeh, Institute of Information Science, Academia Sinica
Abstract

Kleptography was first proposed by Adam Young and Moti Yung in 1996, while algorithm substitution attack was introduced by Mi- hir Bellare et al. as a variation of kleptography in 2014 after the Dual EC incident with the confidential documents revelation by Edward Snowden. These two paradigms share a common goal: to enable attackers to embed covert capabilities into cryptographic implementations while maintaining the appearance of normal functionality. The goal of this paper is to con- solidate existing research on kleptographic attacks, integrate it into a uni- fied definition, and explore future directions for the research in this field. This paper begins by introducing and comparing the two major branches of kleptographic attacks: traditional kleptography and post-Snowden al- gorithm substitution attack, highlighting their theoretical distinctions, threat models, and historical development. Then, it analyzes the spe- cific goals that attackers aim to achieve through such subversions and propose a generalized definition of algorithm substitution attack that in- clude all the goals. The paper also presents practical examples framed within my definition and classify prior research works as either strong or weak attacks based on their structure and undetectability. Finally, it discusses the current landscape of research in kleptographic attacks, and then suggest future directions for the attack and defense perspectives.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
KleptographyAlgorithm Substitution AttackBackdoor CryptographySubversion AttackCryptovirology
Contact author(s)
yehtingyun0952 @ iis sinica edu tw
History
2025-08-20: approved
2025-08-15: received
See all versions
Short URL
https://ia.cr/2025/1480
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1480,
      author = {Ting-Yun Yeh},
      title = {{SoK}: Kleptographic Attacks},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1480},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1480}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.