Paper 2026/167

Breaking and Fixing Spoed

Yan Jia, University of Chinese Academy of Sciences
Peng Wang, University of Chinese Academy of Sciences
Gang Liu, National Key Laboratory of Security Communication
Lei Hu, Institute of Information Engineering
Tingting Guo, School of Cyber Science and Engineering
Shuping Mao, Beijing Electronic Science & Technology Institute
Abstract

Spoed is an authenticated encryption scheme based on compression functions. We show that Spoed fails to achieve its claimed security guarantees with respect to both integrity and confidentiality. In particular, we present a universal forgery attack that succeeds with probability one using only a single encryption query and a single decryption query. The attack exploits a structural weakness in the feedback mechanism of Spoed, allowing internal inputs of the underlying pseudorandom function to coincide during verification. We further show that the same weakness enables efficient plaintext-recovery attacks, permitting recovery of almost the entire plaintext with at most two decryption queries, depending on the associated-data length. We explain why the original security proof of Spoed fails, and identify the mismatch between the collision events used in the H-coefficient analysis and the schemes actual behavior. Finally, we propose a minimally modified variant, fSpoed, and prove that it achieves the originally claimed security bounds under standard assumptions.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Authenticated EncryptionSpoed
Contact author(s)
jiayan22 @ mails ucas ac cn
p-wang @ ucas ac cn
hulei @ iie ac cn
guotingting @ nbut edu cn
maoshuping19 @ mails ucas ac cn
History
2026-02-15: revised
2026-02-01: received
See all versions
Short URL
https://ia.cr/2026/167
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/167,
      author = {Yan Jia and Peng Wang and Gang Liu and Lei Hu and Tingting Guo and Shuping Mao},
      title = {Breaking and Fixing Spoed},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/167},
      year = {2026},
      url = {https://eprint.iacr.org/2026/167}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.