KINDI CCA-security proof

At least 7 years old · documented by

Is KINDI CCA secure without a re-encryption check, as claimed by its published uniqueness lemma?

References

Progress summary

Refreshed
Claimed solved

A 2026 paper shows that KINDI is not secure without re-encryption checking, overturning the published uniqueness argument.

The published KINDI construction claims that checking only d0=dd_0=d suffices: the recovered value is correct and the ciphertext is uniquely generated, supporting CCA security in the random-oracle model when d=0d=0.

Known results

  • The published construction claims (1−elta)(1-elta)-correctness for KINDI whenever the underlying scheme has (1−elta)(1-elta)-correctness, without re-encryption during decapsulation.

July 2026 counterexample

A CryptanalysisBench paper gives a chosen-ciphertext attack exploiting the absence of re-encryption: small ciphertext perturbations can yield the same decapsulated key, so the uniqueness lemma is false. A decryption-reaction oracle can then recover the secret key. The paper attributes discovery of the attack to Claude Mythos 5, which it says produced the result autonomously.

Current status (as of July 2026): The claimed uniqueness lemma and CCA security without re-encryption are refuted; the published construction is insecure in that form.

  • Claude Mythos 5Anthropicsolved2026-07-01evidence
Sources

Solutions 0

No solutions have been posted yet.