RIV for Robust Authenticated Encryption.

FSE(2016)

引用 14|浏览126
暂无评分
摘要
Typical AE schemes are supposed to be secure when used as specified. However, they can --- and often do --- fail miserably when used improperly. As a partial remedy, Rogaway and Shrimpton proposed nonce-misuse-resistant AE MRAE and the first MRAE scheme SIV \"Synthetic Initialization Vector\". This paper proposes RIV \"Robust Initialization Vector\", which extends the generic SIV construction by an additional call to the internal PRF. RIV inherits the full security assurance from SIV, but unlike SIV and other MRAE schemes, RIV is also provably secure when releasing unverified plaintexts. This follows a recent line of research on \"Robust Authenticated Encryption\", similar to the CAESAR candidate AEZ. An AES-based instantiation of RIV runs at less than 1.5 cpb on current x64 processors. Unlike the proposed instantiation of AEZ, which gains speed by relying on reduced-round AES, our instantiation of RIV is provably secure under the single assumption of the AES being secure.
更多
查看译文
关键词
Robustness,Subtle authenticated encryption,Provable security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要