Book Chapter10.1007/978-3-031-17146-8_14
On Committing Authenticated-Encryption
J. Chan,Phillip Rogaway +1 more
16
TL;DR: The notion of committing authenticated-encryption (cAE) was introduced in this paper , where a nonce-based AE (nAE) scheme is shown to commit to a plaintext or ciphertext without hashing one or the other.
read more
Abstract: We provide a strong definition for committing authenticated-encryption (cAE), as well as a framework that encompasses earlier and weaker definitions. The framework attends not only to what is committed but also the extent to which the adversary knows or controls keys. We slot into our framework strengthened cAE-attacks on GCM and OCB. Our main result is a simple and efficient construction, CTX, that makes a nonce-based AE (nAE) scheme committing. The transformed scheme achieves the strongest security notion in our framework. Just the same, the added computational cost (on top of the nAE scheme’s cost) is a single hash over a short string, a cost independent of the plaintext’s length. And there is no increase in ciphertext length compared to the base nAE scheme. That such a thing is possible, let alone easy, upends the (incorrect) intuition that you can’t commit to a plaintext or ciphertext without hashing one or the other. And it motivates a simple and practical tweak to AE-schemes to make them committing.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Journal Article
Compactly Committing Authenticated Encryption Using Encryptment and Tweakable Block Cipher
TL;DR: In this article , a tweakable block cipher instead of AEAD was proposed for the generic construction of Dodis et al. and showed that the proposed construction works as RK ccAEAD.
Compactly Committing Authenticated Encryption Using Encryptment and Tweakable Block Cipher
Shouichi Hirose,Kazuhiko Minematsu +1 more
TL;DR: Compactly committing authenticated encryption using encryptment and tweakable block cipher (ccAEAD) schemes can be built on encryptment and a tweakable block cipher (TBC), leading to simpler and more efficient constructions than Dodis et al.'s methods.
Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and More
TL;DR: The approach is to introduce a new framework that helps to more granularly define context commitment security in terms of what portions of a context are adversarially controlled, and formulate a new notion, called context discoverability security, which can be viewed as analogous to preimage resistance from the hashing literature.
Exploring SHA Instructions and Its Application to AES-based Schemes
Takuro Shiraya,Subhadeep Banik,Tatsuya Ishikawa,Ryoma Ito,Mostafizar Rahman,Kosei Sakamoto,Atsushi Tanaka,Shion Utsumi,Takanori Isobe +8 more
Abstract: In this paper, we explore the potential of improving AES-based schemes by integrating SHA instructions alongside AES instructions, starting from the key observation that SHA instructions can be executed in parallel with AES instructions on modern processors. We investigate conditions for parallel execution, the invocation ratio, and overhead of type conversions, and then provide guidelines for efficient SHA instruction usage with AES instructions. Applying these guidelines, we integrate SHA round functions into the AES-based short-input hash functions of Simpira and Areion, resulting in approximately 50% faster performance by achieving security with fewer iterations. Besides, we apply integration of SHA instructions to AES-based AEAD schemes of AEGIS-128L, which supports a 256-bit tag but has recently been shown to fall short of providing full 256-bit forgery security. We demonstrate that hybrid schemes can achieve 256-bit forgery security for AEGIS-128L while preserving performance.
References
OCB: a block-cipher mode of operation for efficient authenticated encryption
Phillip Rogaway,Mihir Bellare,John Black,Ted Krovetz +3 more
- 05 Nov 2001
TL;DR: It is proved OCB secure, quantifying the adversary's ability to violate the mode's privacy or authenticity in terms of the quality of its block cipher as a pseudorandom permutation (PRP) or as a strong PRP, respectively.
The security and performance of the galois/counter mode (GCM) of operation
David McGrew,John Viega +1 more
- 20 Dec 2004
TL;DR: GCM is shown to be the most efficient mode of operation for high speed packet networks, by using a realistic model of a network crypto module and empirical data from studies of Internet traffic in conjunction with software experiments and hardware designs.
598
The software performance of authenticated-encryption modes
Ted Krovetz,Phillip Rogaway +1 more
- 13 Feb 2011
TL;DR: OCB is found to be substantially faster than either GCM or GCM across a variety of platforms, and there is room for algorithmic improvements to OCB, showing how to trim one blockcipher call and reduce latency.
Formalizing human ignorance
Phillip Rogaway
- 25 Sep 2006
TL;DR: A simple way to sidestep this difficulty that avoids having to key the authors' hash functions is explained, which is to state theorems in a way that prescribes an explicitly-given reduction, normally a black-box one.
166
Reconsidering Generic Composition
Chanathip Namprempre,Phillip Rogaway,Thomas Shrimpton +2 more
- 11 May 2014
TL;DR: In the context of authenticated encryption (AE), generic composition has referred to the construction of an AE scheme by gluing together a conventional (privacy-only) encryption scheme and a MAC as mentioned in this paper.