Paper 2026/1160
Generic Committing Attacks: Zero-Padded Ascon is Less Secure than Expected
Abstract
We study generic committing attacks—where ciphertexts decrypt under more than one context, i.e., key, nonce, associated data—for sponge-based authenticated encryption. As our main contribution, we give three new committing attacks which outperform existing attacks. One of our attacks provides a counterexample showing that the previous proof for the committing security of Ascon-like schemes with zero-padding does not extend to all parameter choices: in case of 128-bit tags and 256-bit zero-padding, the existing analysis claims 192-bit security; our attack reduces this by 62 bits down to 130-bit. Our attacks are applicable to the standardized scheme Ascon. As a further contribution, we analyze existing attack strategies for a generic sponge construction with various design features such as key-blinding, zero-padding, and state-update-functions.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- A major revision of an IACR publication in CRYPTO 2026
- Keywords
- Authenticated EncryptionCommitting SecurityZero-PaddingSpongesAscon
- Contact author(s)
-
nilanjan datta @ tcgcrest org
hrithiknandi crypto @ gmail com
soumitpal378 @ gmail com
yusk sasaki @ ntt com
patrick struck @ uni kn
maximiliane weishaeupl @ ur de - History
- 2026-06-08: approved
- 2026-06-03: received
- See all versions
- Short URL
- https://ia.cr/2026/1160
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1160,
author = {Nilanjan Datta and Hrithik Nandi and Soumit Pal and Yu Sasaki and Patrick Struck and Maximiliane Weishäupl},
title = {Generic Committing Attacks: Zero-Padded Ascon is Less Secure than Expected},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1160},
year = {2026},
url = {https://eprint.iacr.org/2026/1160}
}