Paper 2025/309

A Unified Treatment of Anamorphic Encryption

Wonseok Choi, DGIST
Daniel Collins, New York University, The Hebrew University
Xiangyu Liu, Helmholtz Center for Information Security
Roy Stracovsky, Georgia Institute of Technology
Vassilis Zikas, Georgia Institute of Technology
Abstract

(Receiver) anamorphic encryption, introduced by Persiano et al. [Eurocrypt'22], allows for hiding a covert message $\hat{m}$ (dubbed the anamorphic message) within a public-key ciphertext encrypting another message $m$ so that: (1) a "dictator" adversary with access to the associated secret key cannot detect that such an $\hat{m}$ has been hidden, let alone learn information about it, and (2) knowledge of an additional key (called the double key), which is kept hidden from the dictator, allows to fully recover $\hat{m}$. Anamorphic encryption schemes are typically constructed by mixing symmetric-key and public-key encryption in a clever way, and existing instantiations achieve a variety of novel security guarantees. This has resulted in a disparate landscape of security notions for anamorphic encryption with no systematization and fragmented knowledge about the relationships between them. We put forth a systematic study of anamorphic encryption and summarize our findings as follows. We begin by developing a template for defining indistinguishability-based security for anamorphic encryption. From this, we systematically obtain several new but meaningful definitions for anamorphic encryption. We contextualize all existing and new security notions by proving implications and separations between them. Our methodology also covers asymmetric anamorphic encryption---where the anamorphic message $\hat{m}$ is hidden using public-key techniques---and uncovers a security setting not previously considered: when the dictator and the anamorphic sender collude. Finally, we apply our treatment to capture chosen-ciphertext attacks, which were recently introduced to anamorphic cryptography by Jaeger and Stracovsky [Asiacrypt'24], and propose the first construction of anamorphic encryption that achieves all desirable security properties in this setting.

Note: full version updated

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
Anamorphic EncryptionAnamorphic CryptographyAnamorphism
Contact author(s)
wonseok @ dgist ac kr
d collins @ nyu edu
xiangyu liu @ cispa de
rstracovsky3 @ gatech edu
vzikas @ gatech edu
History
2026-06-17: last of 4 revisions
2025-02-20: received
See all versions
Short URL
https://ia.cr/2025/309
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/309,
      author = {Wonseok Choi and Daniel Collins and Xiangyu Liu and Roy Stracovsky and Vassilis Zikas},
      title = {A Unified Treatment of Anamorphic Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/309},
      year = {2025},
      url = {https://eprint.iacr.org/2025/309}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.