In this paper, we study the security of MAC constructions among those classified by Chen et al. in ASIACRYPT ’21. Precisely, \(F^{\text {EDM}}_{B_2}\)  (or \(\textsf{EWCDM}\) as named by Cogliati and Seurin in CRYPTO ’16), \(F^{\text {EDM}}_{B_3}\) , \(F^{\text {SoP}}_{B_2}\) , \(F^{\text {SoP}}_{B_3}\) (all as named by Chen et al.) are proved to be fully secure up to \(2^n\) MAC queries in the nonce-respecting setting, improving the previous bound of \(\frac{3n}{4}\) -bit security. In particular, \(F^{\text {SoP}}_{B_2}\) and \(F^{\text {SoP}}_{B_3}\) enjoy graceful degradation as the number of queries with repeated nonces grows (when the underlying universal hash function satisfies a certain property called multi-xor-collision resistance). To do this, we develop a new tool, namely, extended Mirror theory for two independent permutations with a wide range of \(\xi _{\max }\) including inequalities. We also present matching attacks on \(F^{\text {EDM}}_{B_4}\) and \(F^{\text {EDM}}_{B_5}\) using \(O(2^{3n/4})\) MAC queries and O(1) verification query without using repeated nonces.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Toward Full n-bit Security and Nonce Misuse Resistance of Block Cipher-Based MACs

  • Wonseok Choi,
  • Jooyoung Lee,
  • Yeongmin Lee

摘要

In this paper, we study the security of MAC constructions among those classified by Chen et al. in ASIACRYPT ’21. Precisely, \(F^{\text {EDM}}_{B_2}\)  (or \(\textsf{EWCDM}\) as named by Cogliati and Seurin in CRYPTO ’16), \(F^{\text {EDM}}_{B_3}\) , \(F^{\text {SoP}}_{B_2}\) , \(F^{\text {SoP}}_{B_3}\) (all as named by Chen et al.) are proved to be fully secure up to \(2^n\) MAC queries in the nonce-respecting setting, improving the previous bound of \(\frac{3n}{4}\) -bit security. In particular, \(F^{\text {SoP}}_{B_2}\) and \(F^{\text {SoP}}_{B_3}\) enjoy graceful degradation as the number of queries with repeated nonces grows (when the underlying universal hash function satisfies a certain property called multi-xor-collision resistance). To do this, we develop a new tool, namely, extended Mirror theory for two independent permutations with a wide range of \(\xi _{\max }\) including inequalities. We also present matching attacks on \(F^{\text {EDM}}_{B_4}\) and \(F^{\text {EDM}}_{B_5}\) using \(O(2^{3n/4})\) MAC queries and O(1) verification query without using repeated nonces.