Critical perspectives on provable security: Fifteen years of "another look" papers

  • We give an overview of our critiques of "proofs" of security and a guide to our papers on the subject that have appeared over the past decade and a half. We also provide numerous additional examples and a few updates and errata.

    Mathematics Subject Classification: Primary: 94A60.


  • Table 1.  Major provable security claims found to have fallacies in the proofs

    Type of protocol Paper with purported proof Paper explaining fallacy
    1) Public key encryption padding (OAEP) Bellare-Rogaway Eurocrypt 1994 [46] Shoup 2002 [273]
    2) Signature schemes Coron Eurocrypt 2002 [116] Kakvi-Kiltz 2012 [199]
    3) Identity-based encryption Boneh-Franklin SIAM J. Comp. 2003 [69] Galindo 2005 [151]
    4) Authenticated encryption (GCM) McGrew-Viega Indocrypt 2004 [235] Iwata-Ohashi-Minematsu 2012 [193]
    5) Key agreement (HMQV) Krawczyk Crypto 2005 [220] Menezes 2007 [236]
    6) Message authentication codes (CBC-MAC and EMAC) Bellare-Pietrzak-Rogaway Crypto 2005 [44] and Pietrzak ICALP 2006 [254] Jha-Nandi 2016 [195]
    7) Triple encryption Bellare-Rogaway Eurocrypt 2006 [47] Gaži-Maurer 2009 [155]
    8) Symmetric encryption (XLS) Ristenpart-Rogaway FSE 2007 [260] Nandi 2014 [245]
    9) Tweakable encryption McGrew-Fluhrer SAC 2007 [234] Chakraborty–Hernández-Jiménez–Sarkar 2015 [90]
    10) Random oracles and Ideal ciphers Coron-Patarin-Seurin Crypto 2008 [125] Holenstein-Künzler-Tessaro 2011 [181]
