Rogue Decryption Failures: Reconciling AE Robustness Notions.
Guy Barwell, Daniel Page, Martijn Stam · 2015
Abstract. An authenticated encryption scheme is deemed secure (AE) if ciphertexts both look like random bitstrings and are unforgeable. AE is a much stronger notion than the traditional IND–CCA. One shortcom-ing of AE as commonly understood is its idealized, all-or-nothing de-cryption: if decryption fails, it will always provide the same single error message and nothing more. Reality often turns out differently: encode-then-encipher schemes often output decrypted ciphertext before verifica-tion has taken place whereas pad-then-MAC-then-encrypt schemes are prone to distinguishable verification failures due to the subtle interac-tion between padding and the MAC-then-encrypt concept. Three recent papers provided what appeared independent and radically different def-initions to model this type of decryption leakage. We reconcile these three works by providing a reference model of secu-rity for authenticated encryption in the face of decryption leakage from invalid queries. Having tracked the development of AE security games, we provide a single expressive framework allowing us to compare and contrast the previous notions. We find that at their core, the notions are essentially equivalent, with their key differences stemming from defini-tional choices independent of the desire to capture real world behaviour.