[openpgp] on the risks of AEAD as signature [was: Re: dr aft-ietf-openpgp-persistent-symmetric-keys-02.txt]
Daniel Kahn Gillmor <[email protected]> Thu, 06 Nov 2025 19:22:42 -0500
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi Daniel, all--
On Tue 2025-11-04 16:26:01 +0000, Daniel Huigens wrote:
> I realized that no, we don't, we could simply use AEAD as a MAC, too,
> by passing the input as additional data, and the empty string as the
> message to encrypt.
Thanks for this note. I'm not enough of a cryptographer to understand
the risks clearly here, but my loose understanding of the "invisible
salamanders" paper suggested that it's possible to create two messages
that would have a colliding AEAD tag (maybe under different keys?):
https://eprint.iacr.org/2019/016
That is, it describes GCM as a "non-committing AE" scheme, and indicates
that a modified primitive is necessary to make it "committing". Is this
sufficient to behave as a signature for our purposes?
I recognize that the theory of normal use here is that the user's
persistent symmetric key itself won't change. But would a maliciously
tampered secret key (and an immutable AEAD tag) risk a message
substitution forgery?
If not, can someone help me understand how this construction is safe?
--dkg, who is really out of his depth
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 324 B)
-----BEGIN PGP SIGNATURE----- wr0EARYKAG8FgmkNO9IJEHgLhU7ZwrSWRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z LnNlcXVvaWEtcGdwLm9yZ0LfwR92D1mH6+KA/TfHAPt5NJfIlBApakCrsQgSfxL7 FiEEY6wRjlsuXWbIioWneAuFTtnCtJYAAMonAQCXNzG15yHPz/pBpX2+TXcf14ME K/UuCwOm+iYNVksI3QD/fLf5oNjJBOomZybW3W9suIof3WarMsj4JehmfD+fgwc= =WaNQ -----END PGP SIGNATURE-----