Paper 2026/240

Do not Mix Models: Revisiting Generic Transforms for Committing Authenticated Encryption

Kazuhiko Minematsu, NEC (Japan), Osaka University
Akiko Inoue, NEC (Japan)
Abstract

Committing security for authenticated encryption (AE) captures the difficulty of constructing a distinct input tuple, including the key, that yields the same ciphertext. This notion is relatively new but has attracted significant attention due to its practical relevance. A promising direction is to design generic transforms that convert any AE scheme into a committing one. A common approach to generic transforms, initiated by the CTX transform (Chan and Rogaway, ESORICS 2022), is to add a hash function that uses part of the AE input/output, assuming the hash is ideal, i.e., a random oracle. Because the baseline AE is assumed to be secure in the standard model, this approach inherently mixes standard-model and idealized-model assumptions. We revisit this approach. We show that a number of state-of-the-art generic transforms relying on a mixed model (Chen and Karadžić, Eurocrypt 2025, and Bhattacharjee et al., ePrint 2024), proposed after CTX, are vulnerable once the hash function is instantiated, by presenting practical attacks against them. Our attacks exploit the fact that the baseline AE may depend on the instantiation of the generic transform, whereas the opposite is not true for the principle of the generic transform. In most cases, the attacks are effective with any instantiation, and the baseline AEs in the attacks have a natural structure, such as Enc-then-MAC with a counter mode encryption. We also demonstrate how to rectify these broken transforms with minimal algorithmic modifications, relying solely on the standard-model assumptions.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Authenticated EncryptionCommitting securityGeneric TransformProvable securityIdealized modelRandom Oracle
Contact author(s)
k-minematsu @ nec com
a_inoue @ nec com
History
2026-02-16: approved
2026-02-13: received
See all versions
Short URL
https://ia.cr/2026/240
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/240,
      author = {Kazuhiko Minematsu and Akiko Inoue},
      title = {Do not Mix Models: Revisiting Generic Transforms for Committing Authenticated Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/240},
      year = {2026},
      url = {https://eprint.iacr.org/2026/240}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.