Paper 2026/2267
Impersonation Resilience of Subversion-Resilient UC Protocols
Abstract
Subversion attacks where the attacker aims to replace parts of a cryptographic system by manipulated parts in an undetectable manner have been shown to model both theoretical and practical attacks such as supply chain attacks. Originally proposed by Young and Yung (CRYPTO 1996), interest in them has increased dramatically after the revelations about the inner workings of intelligence agencies due to Snowden and the following paper by Bellare, Paterson, and Rogaway (CRYPTO 2014). One of the most promising countermeasures against such attacks are cryptographic reverse firewalls, proposed by Mironov and Stephens-Davidowitz (EUROCRYPT 2015), which are small devices used by the parties with the aim to rerandomize the protocol message to remove possible leakage. A wide range of protocols and corresponding firewalls have been developed based on this notion. The usage of such firewalls, however, also introduces another attack surface as an attacker might also corrupt these firewalls. In most works, this problem is either not addressed or treated as if in this case, the complete party using the firewall is compromised. However, as firewalls typically only perform rerandomization without knowledge of secret key material, this is a very coarse over-approximation, as an honest party Alice is now treated as maliciously corrupted. Instead, the main security problem comes from the fact that the firewall can impersonate Alice. In this paper, we introduce the notion of impersonation resilience, which allows us to develop protocols that are also secure against such a corrupted firewall and thus result in an honest complete party. We show a generic compiler that transforms subversion-resilient protocols for commitment or coin toss into protocols that are also impersonation resilient. Following a recent research line, our protocols and security analysis are built on the Universal Composability (UC) framework of Canetti. Of independent interest, we show that existing UC subversion models are either too strong and do not allow secure string commitments, or too weak and allow trivially secure protocols. We addressed this by developing a new, intermediate UC subversion model.
Note: This is the full version of a paper accepted at ASIACRYPT 2026. It contains all appendices and minor corrections in the main body.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Subversion ResilienceUniversal ComposabilityReverse FirewallsImpersonationSecurity Model
- Contact author(s)
-
p arnold @ uni-luebeck de
sebastian berndt @ th-luebeck de
mueller-quade @ kit edu
astrid ottenhues @ kit edu
johannes ottenhues @ kit edu - History
- 2026-09-30: approved
- 2026-09-29: received
- See all versions
- Short URL
- https://ia.cr/2026/2267
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2267,
author = {Paula Arnold and Sebastian Berndt and Jörn Müller-Quade and Astrid Ottenhues and Johannes Ottenhues},
title = {Impersonation Resilience of Subversion-Resilient {UC} Protocols},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2267},
year = {2026},
url = {https://eprint.iacr.org/2026/2267}
}