Breaking POET Authentication with a Single Query.

Jian Guo, Jérémy Jean, Thomas Peyrin, Lei Wang · 2014

Abstract. In this short article, we describe a very practical and simple attack on the au-thentication part of POET authenticated encryption mode proposed at FSE 2014. POET is a provably secure scheme that was designed to resist various attacks where the adversary is allowed to repeat the nonce, or even when the message is output before verifying the validity of the tag when querying the decryption oracle. However, we demonstrate that using only a single encryption query and a negligible amount of computations, even without any spe-cial misuse from the attacker, it is possible to generate many valid ciphertext/tag pairs for POET. Our work shows that one should not use POET for any application where authentication property is required. Furthermore, we propose a possible patch to overcome this particular issue, yet without backing up this patch with a security proof. Key words: authenticated encryption, CAESAR, POE, POET, cryptanalysis, authenticity Authenticated encryption is a very useful cryptographic primitive that might benefit many security engineers and protocol designers, as it provides both privacy and authenticity when sending data. In particular, it avoids the classical threat of a misinterpretation of the privacy-only security provided by a simple encryption mode. The encryption part usually takes as input a message M, some public

Read the paper · More papers on PaperTik