{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,16]],"date-time":"2025-04-16T04:03:14Z","timestamp":1744776194237,"version":"3.40.4"},"reference-count":12,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T00:00:00Z","timestamp":1744675200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T00:00:00Z","timestamp":1744675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Key committing security is a crucial metric of authentication encryption schemes, complementing the fundamental principles of confidentiality and integrity. It ensures that an adversary cannot decrypt a given ciphertext to different sets of key, nonce, and associated data. In this study, we explore a key committing attack on the authenticated encryption stream cipher Tiaoxin-346 from the perspective of internal state collisions. We establish a more rigorous constraint within the FROB framework by identifying a different settings of <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$\\left( k_{2}, Nonce, AD^{*}\\right)$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mfenced>\n                    <mml:msub>\n                      <mml:mi>k<\/mml:mi>\n                      <mml:mn>2<\/mml:mn>\n                    <\/mml:msub>\n                    <mml:mo>,<\/mml:mo>\n                    <mml:mi>N<\/mml:mi>\n                    <mml:mi>o<\/mml:mi>\n                    <mml:mi>n<\/mml:mi>\n                    <mml:mi>c<\/mml:mi>\n                    <mml:mi>e<\/mml:mi>\n                    <mml:mo>,<\/mml:mo>\n                    <mml:mi>A<\/mml:mi>\n                    <mml:mmultiscripts>\n                      <mml:mi>D<\/mml:mi>\n                      <mml:mrow\/>\n                      <mml:mrow>\n                        <mml:mrow\/>\n                        <mml:mo>\u2217<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:mmultiscripts>\n                  <\/mml:mfenced>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> for any specified <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$\\left( k_{1}, Nonce, AD_{1}\\right)$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mfenced>\n                    <mml:msub>\n                      <mml:mi>k<\/mml:mi>\n                      <mml:mn>1<\/mml:mn>\n                    <\/mml:msub>\n                    <mml:mo>,<\/mml:mo>\n                    <mml:mi>N<\/mml:mi>\n                    <mml:mi>o<\/mml:mi>\n                    <mml:mi>n<\/mml:mi>\n                    <mml:mi>c<\/mml:mi>\n                    <mml:mi>e<\/mml:mi>\n                    <mml:mo>,<\/mml:mo>\n                    <mml:mi>A<\/mml:mi>\n                    <mml:msub>\n                      <mml:mi>D<\/mml:mi>\n                      <mml:mn>1<\/mml:mn>\n                    <\/mml:msub>\n                  <\/mml:mfenced>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula>. Specifically, we demonstrate that for the Tiaoxin-346 algorithm, it is possible to find another settings of key <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$k_{2}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msub>\n                    <mml:mi>k<\/mml:mi>\n                    <mml:mn>2<\/mml:mn>\n                  <\/mml:msub>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> and associated data <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$AD^{*}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>A<\/mml:mi>\n                    <mml:mmultiscripts>\n                      <mml:mi>D<\/mml:mi>\n                      <mml:mrow\/>\n                      <mml:mrow>\n                        <mml:mrow\/>\n                        <mml:mo>\u2217<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:mmultiscripts>\n                  <\/mml:mrow>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> with a computational complexity of <jats:italic>O<\/jats:italic>(1), given any key <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$k_{1}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msub>\n                    <mml:mi>k<\/mml:mi>\n                    <mml:mn>1<\/mml:mn>\n                  <\/mml:msub>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> and <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$AD_{1}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>A<\/mml:mi>\n                    <mml:msub>\n                      <mml:mi>D<\/mml:mi>\n                      <mml:mn>1<\/mml:mn>\n                    <\/mml:msub>\n                  <\/mml:mrow>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula>. We provide a detailed explanation of the rationale and a step-by-step methodology for constructing an internal state collision at the seventh round of the update process, aimed at recovering the appropriate <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$AD^{*}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>A<\/mml:mi>\n                    <mml:mmultiscripts>\n                      <mml:mi>D<\/mml:mi>\n                      <mml:mrow\/>\n                      <mml:mrow>\n                        <mml:mrow\/>\n                        <mml:mo>\u2217<\/mml:mo>\n                      <\/mml:mrow>\n                    <\/mml:mmultiscripts>\n                  <\/mml:mrow>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula>. Notably, the computational complexity of our attack is <jats:italic>O<\/jats:italic>(1), significantly lower than the generic attack complexity of <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$O\\left( 2^{64}\\right)$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>O<\/mml:mi>\n                    <mml:mfenced>\n                      <mml:msup>\n                        <mml:mn>2<\/mml:mn>\n                        <mml:mn>64<\/mml:mn>\n                      <\/mml:msup>\n                    <\/mml:mfenced>\n                  <\/mml:mrow>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula>, which effectively violates the key commitment security of Tiaoxin-346. The results of this study contribute to refining the security of authenticated encryption algorithms and offer valuable insights for the design of round update functions in AES-based schemes.<\/jats:p>","DOI":"10.1186\/s42400-024-00331-8","type":"journal-article","created":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T03:01:51Z","timestamp":1744686111000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Key committing attack on Tiaoxin-346 algorithm"],"prefix":"10.1186","volume":"8","author":[{"given":"Nan","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chenhui","family":"Jin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2737-9789","authenticated-orcid":false,"given":"Junwei","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,4,15]]},"reference":[{"key":"331_CR1","first-page":"845","volume-title":"Advances in cryptology\u2014EUROCRYPT 2022, Part II, LNCS","author":"M Bellare","year":"2022","unstructured":"Bellare M, Hoang VT (2022) Efficient schemes for committing authenticated encryption. In: Dunkelman O, Dziembowski S (eds) Advances in cryptology\u2014EUROCRYPT 2022, Part II, LNCS, vol 13276. Springer, pp 845\u2013875"},{"key":"331_CR2","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/978-3-031-17146-8_14","volume-title":"Computer security-ESORICS 2022, LNCS","author":"J Chan","year":"2022","unstructured":"Chan J, Rogaway P (2022) On committing authenticated-encryption. In: Atluri V, Di Pietro R, Jensen CD et al (eds) Computer security-ESORICS 2022, LNCS, vol 13555. Springer, pp 275\u2013294"},{"key":"331_CR3","doi-asserted-by":"publisher","first-page":"135","DOI":"10.46586\/tosc.v2024.i1.135-157","volume":"1","author":"P Derbez","year":"2024","unstructured":"Derbez P, Fouque PA, Isobe T et al (2024) Key committing attacks against AES-based AEAD schemes. IACR Trans Symmetric Cryptol 1:135\u2013157. https:\/\/doi.org\/10.46586\/tosc.v2024.i1.135-157","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"331_CR4","doi-asserted-by":"publisher","first-page":"449","DOI":"10.46586\/tosc.v2017.i1.449-473","volume":"1","author":"P Farshim","year":"2017","unstructured":"Farshim P, Orlandi C, Rosie R (2017) Security of symmetric primitives under incorrect usage of keys. IACR Trans Symmetric Cryptol 1:449\u2013473","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"331_CR5","doi-asserted-by":"crossref","unstructured":"Goldwasser S, Micali S, Rackoff C (1985) The knowledge complexity of interactive proof systems. In: Proceedings of the 17th annual ACM symposium on theory of computing, pp 291\u2013304","DOI":"10.1145\/22145.22178"},{"key":"331_CR6","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/978-3-319-63697-9_3","volume-title":"Advances in cryptology\u2014CRYPTO 2017, Part III, LNCS","author":"P Grubbs","year":"2017","unstructured":"Grubbs P, Lu J, Ristenpart T (2017) Message franking via committing authenticated encryption. In: Katz J, Shacham H (eds) Advances in cryptology\u2014CRYPTO 2017, Part III, LNCS, vol 10403. Springer, pp 66\u201397"},{"key":"331_CR7","unstructured":"Ivica N (2016) Tiaoxin-346 for the CAESAR competition. Retrieved from http:\/\/competitions.cr.yp.to\/round3\/tiaoxinv21.pdf"},{"key":"331_CR8","doi-asserted-by":"publisher","first-page":"14739","DOI":"10.1109\/ACCESS.2022.3147201","volume":"10","author":"MA Jimale","year":"2022","unstructured":"Jimale MA, Aba MR, Kiah ML et al (2022) Authenticated encryption schemes: a systematic review. IEEE Access 10:14739\u201314766. https:\/\/doi.org\/10.1109\/ACCESS.2022.3147201","journal-title":"IEEE Access"},{"key":"331_CR9","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1007\/978-3-031-30634-1_13","volume-title":"Advances in cryptology\u2014EUROCRYPT 2023, LNCS","author":"S Menda","year":"2023","unstructured":"Menda S, Len J, Grubbs P, Ristenpart T (2023) Context discovery and commitment attacks: how to break CCM, EAX, SIV, and more. In: Hazay C, Stam M (eds) Advances in cryptology\u2014EUROCRYPT 2023, LNCS, vol 14007. Springer, pp 379\u2013407"},{"key":"331_CR10","doi-asserted-by":"publisher","unstructured":"Yao AC (1982) Protocols for secure computations. In: Proceedings of the 23rd annual symposium on foundations of computer science, pp 160\u2013164. https:\/\/doi.org\/10.1109\/SFCS.1982.38","DOI":"10.1109\/SFCS.1982.38"},{"issue":"12","key":"331_CR11","doi-asserted-by":"publisher","first-page":"1475","DOI":"10.1631\/FITEE.1800576","volume":"19","author":"F Zhang","year":"2018","unstructured":"Zhang F, Liang Z, Yang B et al (2018) Survey of design and security evaluation of authenticated encryption algorithms in the CAESAR competition. Front Inf Technol Electron Eng 19(12):1475\u20131499","journal-title":"Front Inf Technol Electron Eng"},{"key":"331_CR12","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1016\/j.ins.2018.10.024","volume":"476","author":"C Zhao","year":"2019","unstructured":"Zhao C, Zhao S, Zhao M et al (2019) Secure multi-party computation: theory, practice and applications. Inf Sci 476:357\u2013372. https:\/\/doi.org\/10.1016\/j.ins.2018.10.024","journal-title":"Inf Sci"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-024-00331-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-024-00331-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-024-00331-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T03:01:53Z","timestamp":1744686113000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-024-00331-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,15]]},"references-count":12,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["331"],"URL":"https:\/\/doi.org\/10.1186\/s42400-024-00331-8","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,15]]},"assertion":[{"value":"30 July 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 October 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 April 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"25"}}