Paper 2026/2110
Forkcipher-Based Committing Security from Explicit Collision Security Assumptions
Abstract
Context-committing security binds an authenticated encryption (AE) ciphertext uniquely to its encryption context. Many conventional AE schemes lack this guarantee, while most generic committing transforms rely on idealized primitives. We develop committing AE from explicit forkcipher collision-resistance properties: $\mathsf{fCR}$ and zero-message collision resistance ($\mathsf{zmCR}$). For an $n$-to-$2n$-bit forkcipher, we establish matching query complexities of order $2^{n/2}$ and $2^n$, respectively. MILP- and SAT-based differential and reduced-round collision analyses of $\textsf{ForkSkinny-128-384}$ support the corresponding generic security levels for the full-round primitive. We also analyze collisions in ButterKnife and ZIP-AES. We lift $\mathsf{fCR}$ and $\mathsf{zmCR}$ through FCPRF and FixM to fixed-length collision-resistant PRFs. We introduce nonce-based PRF security to capture the nonce-respecting pseudorandomness needed by our constructions, and construct FHashN, proving its variable-input-length collision resistance, pseudorandomness, and nonce-based pseudorandomness. We present AEaH-2K, a two-key variant of AEaH combining secure AE with a variable-input-length collision-resistant PRF. Including the AE key in the commitment input gives confidentiality, authenticity, and CMT-4 security in the standard model. We also construct $\textsf{FCTR-CMT}$, an AEAD mode using a single forkcipher, and prove nonce-respecting privacy, authenticity, and CMT-4 security. With FHashN based on FCPRF, $\textsf{FCTR-CMT}$ achieves $n$-bit confidentiality and $n/2$-bit authenticity and CMT-4 security; with FixM, all 3 reach $n$ bits. All construction proofs reduce to explicit pseudorandomness and collision-resistance assumptions.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- Committing SecurityForkciphersPRFs
- Contact author(s)
-
elena andreeva @ tuwien ac at
maria eichlseder @ tugraz at
simon gerhalter @ tugraz at
marcel nageler @ tugraz at
oliver popa @ tugraz at
andreas weninger @ house-of-innovation com - History
- 2026-09-22: approved
- 2026-09-19: received
- See all versions
- Short URL
- https://ia.cr/2026/2110
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2110,
author = {Elena Andreeva and Maria Eichlseder and Simon Gerhalter and Marcel Nageler and Oliver Christoph Popa and Andreas Weninger},
title = {Forkcipher-Based Committing Security from Explicit Collision Security Assumptions},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2110},
year = {2026},
url = {https://eprint.iacr.org/2026/2110}
}