[openpgp] Re: on the risks of AEAD as signature [was: Re : draft-ietf-openpgp-persistent-symmetric-keys-02.txt]

Andrew Gallagher <[email protected]> Fri, 7 Nov 2025 18:16:04 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 07/11/2025 00:22, Daniel Kahn Gillmor wrote:
>
> Thanks for this note.  I'm not enough of a cryptographer to understand
> the risks clearly here, but my loose understanding of the "invisible
> salamanders" paper suggested that it's possible to create two messages
> that would have a colliding AEAD tag (maybe under different keys?):
> 
>     https://eprint.iacr.org/2019/016
> 
> That is, it describes GCM as a "non-committing AE" scheme, and indicates
> that a modified primitive is necessary to make it "committing".  Is this
> sufficient to behave as a signature for our purposes?

Isn't this why we specified an HKDF step in SEIPDv2? We could do the 
same thing here.

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]