@alwayscurious@infosec.exchange
2026-09-18 21:49 UTC
Replies (1)
-
@sophieschmieg@infosec.exchange 2026-09-18 22:08
@alwayscurious@infosec.exchange @mei@donotsta.re these proof types serve slightly different purposes: reduction proofs are very useful when constructing cryptographic primitives. I.e. you want to show that AES-CTR is IND-CPA secure as long as AES is a secure PRP. The direct proofs you mentioned are usually used to prove protocols secure, using the properties that the primitives are shown to have to construct an interaction that is secure, as long as the components are secure. They usually could also be written as reduction proofs (assume the protocol is broken by attacker A. Since we verified the certificate, this means the certificate has a valid signature without the adversary having access to the private key, we can construct an EUF-CMA attacker A' that calls A, simulating the protocol to it using its oracle that will now win its attack game). It's just that for a protocol analysis this type of reduction proof is usually overkill and doesn't convey information, so it's merely implied and left to the reader.