Paper 2026/167
Breaking and Fixing Spoed
Abstract
Spoed is an authenticated encryption scheme based on compression functions. We show that Spoed fails to achieve its claimed security guarantees with respect to both integrity and confidentiality. In particular, we present a universal forgery attack that succeeds with probability one using only a single encryption query and a single decryption query. The attack exploits a structural weakness in the feedback mechanism of Spoed, allowing internal inputs of the underlying pseudorandom function to coincide during verification. We further show that the same weakness enables efficient plaintext-recovery attacks, permitting recovery of almost the entire plaintext with at most two decryption queries, depending on the associated-data length. We explain why the original security proof of Spoed fails, and identify the mismatch between the collision events used in the H-coefficient analysis and the schemes actual behavior. Finally, we propose a minimally modified variant, fSpoed, and prove that it achieves the originally claimed security bounds under standard assumptions.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Authenticated EncryptionSpoed
- Contact author(s)
-
jiayan22 @ mails ucas ac cn
p-wang @ ucas ac cn
hulei @ iie ac cn
guotingting @ nbut edu cn
maoshuping19 @ mails ucas ac cn - History
- 2026-02-15: revised
- 2026-02-01: received
- See all versions
- Short URL
- https://ia.cr/2026/167
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/167,
author = {Yan Jia and Peng Wang and Gang Liu and Lei Hu and Tingting Guo and Shuping Mao},
title = {Breaking and Fixing Spoed},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/167},
year = {2026},
url = {https://eprint.iacr.org/2026/167}
}