Paper 2026/1275

The Indifferentiability of the Duplex and its Practical Applications

Jean Paul Degabriele, Technology Innovation Institute
Marc Fischlin, TU Darmstadt
Jérôme Govinden, TU Darmstadt
Abstract

The Duplex construction, introduced by Bertoni et al. (SAC 2011), is the Swiss Army knife of permutation-based cryptography. It can be used to realise a variety of cryptographic objects—ranging from hash functions and MACs, to authenticated encryption and symmetric ratchets. Testament to this is the STROBE protocol framework which is a software cryptographic library based solely on the Duplex combined with a rich set of function calls. While prior works have typically focused their attention on specific uses of the Duplex, our focus here is its indifferentiability. More specifically, we consider the indifferentiability of the Duplex construction from an online random oracle—an idealisation which shares its same interface. As one of our main results we establish the indifferentiability of the Duplex from an online random oracle. However indifferentiability only holds for the standard Duplex construction and we show that the full-state variant of the Duplex cannot meet this notion. Our indifferentiability theorem provides the theoretical justification for the security of the Duplex in a variety of scenarios, amongst others, its use as a general-purpose cryptographic primitive in the STROBE framework. Next we move our attention to AEAD schemes based on the Duplex, namely SpongeWrap, which is the basis for NIST's Lightweight Cryptography standard Ascon. We harness the power of indifferentiability by establishing that SpongeWrap offers security against key-dependent message inputs, related-key attacks, and is also committing.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
A major revision of an IACR publication in ASIACRYPT 2023
DOI
10.1007/978-981-99-8742-9_8
Keywords
duplexindifferentiabilityonline random oracleauthenticated encryption
Contact author(s)
jeanpaul degabriele @ tii ae
marc fischlin @ cryptoplexity de
jerome govinden @ tu-darmstadt de
History
2026-06-19: approved
2026-06-17: received
See all versions
Short URL
https://ia.cr/2026/1275
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1275,
      author = {Jean Paul Degabriele and Marc Fischlin and Jérôme Govinden},
      title = {The Indifferentiability of the Duplex and its Practical Applications},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1275},
      year = {2026},
      doi = {10.1007/978-981-99-8742-9_8},
      url = {https://eprint.iacr.org/2026/1275}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.