[openpgp] Re: on the risks of AEAD as signature

Falko Strenzke <[email protected]> Tue, 11 Nov 2025 07:37:43 +0100
Newsgroups gmane.ietf.openpgp
Organization MTG AG
Message-ID <[email protected]>
Hi Daniel,

Am 10.11.25 um 19:56 schrieb Daniel Kahn Gillmor:
> Hi Falko--
>
> Thanks for nudging this conversation in a more concrete direction:
>
> On Mon 2025-11-10 08:52:04 +0100, Falko Strenzke wrote:
>> The main question is who is going to forge an AEAD message to fool whom.
>> For the verification of a MAC or AEAD protected message the secret key
>> is needed. Obviously, with the possession of the secret key, signature
>> forgeries can be performed. I suggest to first consider whether there is
>> a valid attack scenario here in the first place.
> I expect a symmetric signature to be used to record something that would
> otherwise be more expensive to recompute, like an asymmetric signature
> verification.
>
> So for example:
>
> - Bob might send Alice a message X, signed using Bob's secret key b
>    (with corresponding certificate B), via a signature B_X.
>
> - Alice verifies the signature B_X over X with certificate B, and caches
>    the result by appending her own symmetric signature A_X to the message.
>    She uses symmetric secret key A (known only to her).
>
> The rationale here would be if it's cheaper for Alice to verify <X,A_X>
> than to recompute Verify(X,B_X).  Alternately, A_X might be smaller/more
> compact than B_X, so maybe Alice wants to conserve storage by replacing
> B_X with A_X.
>
> The security "game" here might be for Bob (who controls the creation of
> X and B_X and might be able to see A_X) (or another attacker, who might
> at least know X, B_X, and A_X) to be able to produce a variant X' that
> *also* validates against A_X.  If the attacker can do that, then Alice's
> signature cache actually introduces a security flaw, because Bob doesn't
> have to make a non-repudiable assertion in order for Alice to believe
> that he had signed the message.

That is not a concern in the view of lack of key commitment. Any attack 
scenario you describe here would mean that AEAD is broken. Lack of key 
commitment is something researchers were aware of and which was 
intentionally tolerated when designing these schemes. It only allows 
attacks for someone who controls the AEAD keys. The attack is always to 
find two or more keys, s.th. there are ambiguous decryption results for 
the same ciphertext and tag.

Best regards,
Falko

>
> I'm not claiming i know of a functional attack in such a game.  I'm just
> observing that the existence of the "invisible salamanders" attack
> suggests that at least GCM AEAD doesn't provide the security one might
> expect from a message signature or even a checksum.
>
> I'd be very happy to see analysis that suggests this is not an issue.
>
>      --dkg
>
> _______________________________________________
> openpgp mailing list [email protected]
> To unsubscribe send an email [email protected]
-- 

*MTG AG*
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: [email protected]
Web: mtg.de <https://www.mtg.de>

------------------------------------------------------------------------

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed