CryptoDB
Ask Your Cryptographer if Context-Committing AEAD Is Right for You
Authors: | |
---|---|
Download: | |
Presentation: | Slides |
Abstract: | This talk will make the case, on behalf of a group of authors of many of the recent results on commitment in AEAD, that the community should prioritize and standardize AEAD designs that achieve commitment to the key, associated data, and nonce. We call this context commitment. The main benefit of such schemes is that they preclude practitioners from having to make choices about what parts of the context should be committing. While context commitment has not yet seen the same kind of attacks in practice as key commitment, we expect them to be discovered and, to get ahead of attackers, standardization efforts should therefore target context commitment. We will start our presentation by defining context commitment [BH22], highlighting in particular how it is not formally implied by key commitment. We next discuss new attacks that exploit this gap, including showing context-commitment attacks on recently proposed key commitment-secure schemes [Kra19, §3.1.1], [ADG+22, §5.3], and [D+22]. These hint at a rich landscape of possible attacks, and we briefly discuss frameworks that explore this landscape [BH22,CR22,MLGR22]. Finally, we provide an overview of recent proposals for new AEAD schemes that achieve context commitment, and discuss avenues for future work. |
Video: | https://youtu.be/Xh849Ij3lhU?t=2766 |
BibTeX
@misc{rwc-2023-35476, title={Ask Your Cryptographer if Context-Committing AEAD Is Right for You}, note={Video at \url{https://youtu.be/Xh849Ij3lhU?t=2766}}, howpublished={Talk given at RWC 2023}, author={Mihir Bellare and John Chan and Paul Grubbs and Viet Tung Hoang and Sanketh Menda and Julia Len and Thomas Ristenpart and Phillip Rogaway}, year=2023 }