[openpgp] on the risks of AEAD as signature [was: Re: dr aft-ietf-openpgp-persistent-symmetric-keys-02.txt]

Daniel Kahn Gillmor <[email protected]> Thu, 06 Nov 2025 19:22:42 -0500
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi Daniel, all--

On Tue 2025-11-04 16:26:01 +0000, Daniel Huigens wrote:
> I realized that no, we don't, we could simply use AEAD as a MAC, too,
> by passing the input as additional data, and the empty string as the
> message to encrypt.

Thanks for this note.  I'm not enough of a cryptographer to understand
the risks clearly here, but my loose understanding of the "invisible
salamanders" paper suggested that it's possible to create two messages
that would have a colliding AEAD tag (maybe under different keys?):

   https://eprint.iacr.org/2019/016

That is, it describes GCM as a "non-committing AE" scheme, and indicates
that a modified primitive is necessary to make it "committing".  Is this
sufficient to behave as a signature for our purposes?

I recognize that the theory of normal use here is that the user's
persistent symmetric key itself won't change.  But would a maliciously
tampered secret key (and an immutable AEAD tag) risk a message
substitution forgery?

If not, can someone help me understand how this construction is safe?

             --dkg, who is really out of his depth

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 324 B)
-----BEGIN PGP SIGNATURE-----

wr0EARYKAG8FgmkNO9IJEHgLhU7ZwrSWRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z
LnNlcXVvaWEtcGdwLm9yZ0LfwR92D1mH6+KA/TfHAPt5NJfIlBApakCrsQgSfxL7
FiEEY6wRjlsuXWbIioWneAuFTtnCtJYAAMonAQCXNzG15yHPz/pBpX2+TXcf14ME
K/UuCwOm+iYNVksI3QD/fLf5oNjJBOomZybW3W9suIof3WarMsj4JehmfD+fgwc=
=WaNQ
-----END PGP SIGNATURE-----