Paper 2026/1594

Breaking ADP-Based Witness Encryption

Muhammad El Gebali, [[alloc] init]
Yaroslav Rebenko, [[alloc] init]
Markus Schofnegger, [[alloc] init]
Lev Soukhanov, [[alloc] init]
Abstract

Witness encryption (WE) allows one party to encrypt a message under an arbitrary satisfiable circuit, so that anyone holding a satisfying input can decrypt. Efficient WE enables numerous modern applications, such as identity-based and attribute-based encryption. Recent candidates for efficient WE base their security on rank properties of structured ciphertext matrices, which encode the validity of a given witness. This shrinks ciphertext sizes considerably compared to previous constructions, but rests on heuristic arguments rather than security reductions. We describe two attacks against two such constructions, namely the affine determinant program (ADP) construction from 2020 and its arithmetic extension, the AADP, from 2026. The first attack observes that for sparse circuits, the natural regime for both schemes, commutators formed from the public ciphertext matrices have unexpectedly low rank. Elementary linear algebra on these matrices then recovers the encrypted message directly from the public ciphertext, without knowledge of any witness, and hence breaks the security of both schemes. The second attack linearizes the nearly-skew-symmetric (NSS) variant of the ADP construction, recovering the encryption randomness and the message. To our knowledge, ours are the first attacks against these WE candidates, and we verify both in practice.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
witness encryptionalgebraic attackscryptanalysis
Contact author(s)
gebali @ allocinit xyz
yar @ allocinit xyz
markus @ allocinit xyz
lev @ allocinit xyz
History
2026-08-06: approved
2026-08-03: received
See all versions
Short URL
https://ia.cr/2026/1594
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1594,
      author = {Muhammad El Gebali and Yaroslav Rebenko and Markus Schofnegger and Lev Soukhanov},
      title = {Breaking {ADP}-Based Witness Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1594},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1594}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.