Paper 2026/2110

Forkcipher-Based Committing Security from Explicit Collision Security Assumptions

Elena Andreeva, TU Wien
Maria Eichlseder, Graz University of Technology
Simon Gerhalter, Graz University of Technology
Marcel Nageler, Graz University of Technology
Oliver Christoph Popa, Graz University of Technology
Andreas Weninger, TU Wien
Abstract

Context-committing security binds an authenticated encryption (AE) ciphertext uniquely to its encryption context. Many conventional AE schemes lack this guarantee, while most generic committing transforms rely on idealized primitives. We develop committing AE from explicit forkcipher collision-resistance properties: $\mathsf{fCR}$ and zero-message collision resistance ($\mathsf{zmCR}$). For an $n$-to-$2n$-bit forkcipher, we establish matching query complexities of order $2^{n/2}$ and $2^n$, respectively. MILP- and SAT-based differential and reduced-round collision analyses of $\textsf{ForkSkinny-128-384}$ support the corresponding generic security levels for the full-round primitive. We also analyze collisions in ButterKnife and ZIP-AES. We lift $\mathsf{fCR}$ and $\mathsf{zmCR}$ through FCPRF and FixM to fixed-length collision-resistant PRFs. We introduce nonce-based PRF security to capture the nonce-respecting pseudorandomness needed by our constructions, and construct FHashN, proving its variable-input-length collision resistance, pseudorandomness, and nonce-based pseudorandomness. We present AEaH-2K, a two-key variant of AEaH combining secure AE with a variable-input-length collision-resistant PRF. Including the AE key in the commitment input gives confidentiality, authenticity, and CMT-4 security in the standard model. We also construct $\textsf{FCTR-CMT}$, an AEAD mode using a single forkcipher, and prove nonce-respecting privacy, authenticity, and CMT-4 security. With FHashN based on FCPRF, $\textsf{FCTR-CMT}$ achieves $n$-bit confidentiality and $n/2$-bit authenticity and CMT-4 security; with FixM, all 3 reach $n$ bits. All construction proofs reduce to explicit pseudorandomness and collision-resistance assumptions.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Committing SecurityForkciphersPRFs
Contact author(s)
elena andreeva @ tuwien ac at
maria eichlseder @ tugraz at
simon gerhalter @ tugraz at
marcel nageler @ tugraz at
oliver popa @ tugraz at
andreas weninger @ house-of-innovation com
History
2026-09-22: approved
2026-09-19: received
See all versions
Short URL
https://ia.cr/2026/2110
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2110,
      author = {Elena Andreeva and Maria Eichlseder and Simon Gerhalter and Marcel Nageler and Oliver Christoph Popa and Andreas Weninger},
      title = {Forkcipher-Based Committing Security from Explicit Collision Security Assumptions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2110},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2110}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.