The \(\textsf{GCM}\) authenticated encryption (AE) scheme is one of the most widely used AE schemes in the world, while it suffers from risk of nonce misuse, short message length per encryption and an insufficient level of security. The goal of this paper is to design new AE schemes achieving stronger provable security in the standard model and accepting longer nonces (or providing nonce misuse resistance), with the design rationale behind \(\textsf{GCM}\) . As a result, we propose two enhanced variants of \(\textsf{GCM}\) and \(\textsf{GCM}\text {-}\textsf{SIV}\) , dubbed \(\textsf{eGCM}\) and \(\textsf{eGCM}\text {-}\textsf{SIV}\) , respectively. \(\textsf{eGCM}\) and \(\textsf{eGCM}\text {-}\textsf{SIV}\) are built on top of a new \(\textsf{CENC}\) -type encryption mode, dubbed \(\textsf{eCTR}\) : using 2n-bit counters, \(\textsf{eCTR}\) enjoys beyond-birthday-bound security without significant loss of efficiency. \(\textsf{eCTR}\) is combined with an almost uniform and almost universal hash function, yielding a variable input-length variable output-length pseudorandom function, dubbed \(\textsf{HteC}\) . \(\textsf{GCM}\) and \(\textsf{GCM}\text {-}\textsf{SIV}\) are constructed using \(\textsf{eCTR}\) and \(\textsf{HteC}\) as building blocks. \(\textsf{eGCM}\) and \(\textsf{eGCM}\text {-}\textsf{SIV}\) accept nonces of arbitrary length, and provide almost the full security (namely, n-bit security when they are based on an n-bit block cipher) for a constant maximum input length, under the assumption that the underlying block cipher is a pseudorandom permutation (PRP). Their efficiency is also comparable to \(\textsf{GCM}\) in terms of the rate and the overall speed.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Making GCM Great Again: Toward Full Security and Longer Nonces

  • Woohyuk Chung,
  • Seongha Hwang,
  • Seongkwang Kim,
  • Byeonghak Lee,
  • Jooyoung Lee

摘要

The \(\textsf{GCM}\) authenticated encryption (AE) scheme is one of the most widely used AE schemes in the world, while it suffers from risk of nonce misuse, short message length per encryption and an insufficient level of security. The goal of this paper is to design new AE schemes achieving stronger provable security in the standard model and accepting longer nonces (or providing nonce misuse resistance), with the design rationale behind \(\textsf{GCM}\) . As a result, we propose two enhanced variants of \(\textsf{GCM}\) and \(\textsf{GCM}\text {-}\textsf{SIV}\) , dubbed \(\textsf{eGCM}\) and \(\textsf{eGCM}\text {-}\textsf{SIV}\) , respectively. \(\textsf{eGCM}\) and \(\textsf{eGCM}\text {-}\textsf{SIV}\) are built on top of a new \(\textsf{CENC}\) -type encryption mode, dubbed \(\textsf{eCTR}\) : using 2n-bit counters, \(\textsf{eCTR}\) enjoys beyond-birthday-bound security without significant loss of efficiency. \(\textsf{eCTR}\) is combined with an almost uniform and almost universal hash function, yielding a variable input-length variable output-length pseudorandom function, dubbed \(\textsf{HteC}\) . \(\textsf{GCM}\) and \(\textsf{GCM}\text {-}\textsf{SIV}\) are constructed using \(\textsf{eCTR}\) and \(\textsf{HteC}\) as building blocks. \(\textsf{eGCM}\) and \(\textsf{eGCM}\text {-}\textsf{SIV}\) accept nonces of arbitrary length, and provide almost the full security (namely, n-bit security when they are based on an n-bit block cipher) for a constant maximum input length, under the assumption that the underlying block cipher is a pseudorandom permutation (PRP). Their efficiency is also comparable to \(\textsf{GCM}\) in terms of the rate and the overall speed.