Universal composability (UC)

 

tl;dr: I wish there was better stuff around than UC for modelling security of cryptosystems.

$ \def\sid{\mathsf{sid}} \def\F{\mathcal{F}} \def\Fsig{\F_\mathsf{SIG}} \def\Sim{\mathcal{S}} $

Terminology

To wrap your head around the UC framework, there are several concepts you must understand:

  • ideal functionality $\F$
    • a specification for what a cryptographic protocol should (not) do
  • protocol $\pi$
    • an concrete implementation of an ideal functionality
  • real-world adversary $\Adv$
  • ideal-world adversary $=$ simulator $\Sim$
  • environment
  • interactive Turing machine (ITM)
  • interactive Turing machine instance (ITI)
  • emulation/simulation
  • session
  • session ID $\sid$
    • each copy of an
  • $\F$-hybrid model
    • when a protocol $\pi$ (concrete) has ideal access to an unbounded number of copies of an ideal functionality $\F$
  • composition theorem

Historical papers

  • first UC paper1
  • “simpler” UC for MPC2
  • “simpler” iUC paper3: still not very simplified, IMO.
  • A very formally worked-out example of a UC proof for PAKE4
  • EasyUC paper5: UC proofs in EasyCrypt
  • IPDL paper6: also mechanizes UC proofs, AFAICT

Negatives

  • The initial UC ideal functionality for a digital signature $\Fsig$1, which should be simple, had to be redefined several times due to subtle issues
    • $\Fsig$ could not be shared/reused7, such as when a player reuses the same signing keys across multiple authenticated key exchange sessions.
    • $\Fsig$ could not actually be realized in UC8.
    • $\Fsig$ allowed the same $(m,\sigma,\pk)$ tuple to pass verification today but fail tomorrow, for some $\pk$’s: a non-deterministic verification / repudiation issue9
    • 10
  • UC ideal functionalities are easy to get wrong $\Rightarrow$ should still formalize game-based security properties for them and prove them11
    • Same could be said about non-UC ones too, arguably.
  • The composability you get is not always the composability you want: e.g., cannot compose \(\mathcal{F}_\mathsf{ZK}\) with \(\mathcal{F}_\mathsf{Sig}\) to get a ZKPoK of a signature for anonymous credentials, say12.
  • UC functionalities are not stable, nor often reused in practice: papers frequently redefine them13.

Appendix: Universal composition with joint state (JUC, or “juicy”)

The problem:

All known composition theorems [..] assume that, at least as far as the honest parties are concerned, the local state of each one of the composed protocol instances is disjoint from the local states of all the other protocol instances run by the party.

Q: What counts as state here?

Canetti and Rabin add support for functionalities with joint-state7. e.g.,:

  • many users running many instances of a key-exchange protocol, exchanging keys with multiple other users, but using the same PKI functionality
  • secure communication protocols, where multiple protocol instances use the same instance of a public-key signature or encryption scheme

(In general, concurrent executions of the same ideal functionality that reuses a PKI or a CRS functionality.)

A diagram from the paper (think of $\rho$ as the CRS sub-protocol or the PKI sub-protocol):

Universal composition with joint state: many independent copies of rho versus a single joint copy rho-hat

Their paper also gives a nice summary of what UC is, with more details in the appendix:

In order to allow proving the universal composition theorem, the notion of emulation [..] is considerably stronger than previous ones. Traditionally, the model of computation includes the parties running the protocol and an adversary, \(\mathcal{A}\), that controls the communication channels and potentially corrupts parties. “Emulating an ideal process” means that for any adversary \(\mathcal{A}\) there should exist an “ideal process adversary” (or, simulator) \(\mathcal{S}\) that causes the outputs of the parties in the ideal process to have similar distribution to the outputs of the parties in an execution of the protocol. In the UC framework the requirement on \(\mathcal{S}\) is more stringent. Specifically, an additional entity, called the environment \(\mathcal{Z}\), is introduced. The environment generates the inputs to all parties, reads all outputs, and in addition interacts with the adversary in an arbitrary way throughout the computation. A protocol is said to securely realize a given ideal functionality \(\mathcal{F}\) if for any “real-life” adversary \(\mathcal{A}\) that interacts with the protocol and the environment there exists an “ideal-process adversary” \(\mathcal{S}\), such that no environment \(\mathcal{Z}\) can tell whether it is interacting with \(\mathcal{A}\) and parties running the protocol, or with \(\mathcal{S}\) and parties that interact with \(\mathcal{F}\) in the ideal process. In a sense, here \(\mathcal{Z}\) serves as an “interactive distinguisher” between a run of the protocol and the ideal process with access to \(\mathcal{F}\).

References

For cited works, see below 👇👇

  1. Universally Composable Security: A New Paradigm for Cryptographic Protocols, by Ran Canetti, in Cryptology ePrint Archive, Report 2000/067, 2000, [URL] ↩ ↩2

  2. A Simpler Variant of Universally Composable Security for Standard Multiparty Computation, by Ran Canetti and Asaf Cohen and Yehuda Lindell, in Cryptology {ePrint} Archive, Paper 2014/553, 2014, [URL] ↩

  3. iUC}: Flexible Universal Composability Made Simple, by Jan Camenisch and Stephan Krenn and Ralf Kuesters and Daniel Rausch, in Cryptology {ePrint} Archive, Paper 2019/1073, 2019, [URL] ↩

  4. UC}-Security of Encrypted Key Exchange: A Tutorial, by Jiayu Xu, in Cryptology {ePrint} Archive, Paper 2025/237, 2025, [URL] ↩

  5. EasyUC}: Using {EasyCrypt} to Mechanize Proofs of Universally Composable Security, by Ran Canetti and Alley Stoughton and Mayank Varia, in Cryptology {ePrint} Archive, Paper 2019/582, 2019, [URL] ↩

  6. IPDL}: A Simple Framework for Formally Verifying Distributed Cryptographic Protocols, by Greg Morrisett and Elaine Shi and Kristina Sojakova and Xiong Fan and Joshua Gancher, in Cryptology {ePrint} Archive, Paper 2021/147, 2021, [URL] ↩

  7. Universal Composition with Joint State, by Ran Canetti and Tal Rabin, in Cryptology {ePrint} Archive, Paper 2002/047, 2002, [URL] ↩ ↩2

  8. How to Break and Repair a Universally Composable Signature Functionality, by Michael Backes and Dennis Hofheinz, in Cryptology {ePrint} Archive, Paper 2003/240, 2003, [URL] ↩

  9. Universally Composable Signatures, Certification and Authentication, by Ran Canetti, in Cryptology {ePrint} Archive, Paper 2003/239, 2003, [URL] ↩

  10. On Composable Security for Digital Signatures, by Christian Badertscher and Ueli Maurer and Björn Tackmann, in Cryptology {ePrint} Archive, Paper 2018/015, 2018, [URL] ↩

  11. Are ideal functionalities really ideal?, by Myrto Arapinis and Véronique Cortier and Hubert de Groote and Charlie Jacomme and Steve Kremer, in Cryptology {ePrint} Archive, Paper 2025/2125, 2025, [URL] ↩

  12. Multi-Protocol UC and its Use for Building Modular and Efficient Protocols, by Jan Camenisch and Manu Drijvers and Björn Tackmann, in Cryptology ePrint Archive, Paper 2019/065, 2019, [URL] ↩

  13. A Framework for the Sound Specification of Cryptographic Tasks, by Juan A. Garay and Aggelos Kiayias and Hong-Sheng Zhou, in Cryptology {ePrint} Archive, Paper 2008/132, 2008, [URL] ↩