RIV for Robust Authenticated Encryption

RIV for Robust Authenticated Encryption
复制标题

RIV 用于可靠的认证加密

DOI:
10.1007/978-3-662-52993-5_2
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Jakob Wenzel
Jakob Wenzel
中科院分区:
--
文献类型:
--
作者:
Farzaneh Abed;Christian Forler;Eik List;Stefan Lucks;Jakob Wenzel

文献摘要

参考文献

被引文献

相似文献

典型的AE方案在按指定使用时应该是安全的。然而,当使用不当时,它们可能--而且经常--失败得很惨。作为部分补救措施,Rogaway和Shrimpton提出了(nonce-)防误用AE(MRAE)和第一个MRAE方案SIV(“合成的错误向量”)。本文提出了RIV(“Robust RRAE Vector”)方案,它通过对内部PRF的额外调用扩展了一般的SIV构造,继承了SIV的全部安全保证,但与SIV和其他MRAE方案不同,RIV在释放未经验证的明文时也是可证明安全的。这遵循了最近关于“鲁棒认证加密”的研究路线,类似于CAESAR候选AEZ. AES的RIV实例化在当前x64处理器上的运行速度低于1.5 cpb。与AEZ的实例化不同,AEZ的实例化通过依赖于减少回合的AES来获得速度,我们的RIV实例化在AES是安全的单一假设下是可证明安全的。
Typical AE schemes are supposed to be secure when used as specified. However, they can – and often do – fail miserably when used improperly. As a partial remedy, Rogaway and Shrimpton proposed (nonce-)misuse-resistant AE (MRAE) and the first MRAE scheme SIV (“Synthetic Initialization Vector”). This paper proposesRIV(“Robust Initialization Vector”), which extends the generic SIV construction by an additional call to the internal PRF.RIVinherits the full security assurance from SIV, but unlike SIV and other MRAE schemes,RIVis also provably secure when releasing unverified plaintexts. This follows a recent line of research on“Robust Authenticated Encryption”, similar to the CAESAR candidate AEZ.An AES-based instantiation ofRIVruns at less than 1.5 cpb on current x64 processors. Unlike the proposed instantiation of AEZ, which gains speed by relying on reduced-round AES, our instantiation ofRIVis provably secure under the single assumption of the AES being secure.
一种新的内积算法
DOI: --
发表时间: 1968
影响因子: 3.7
作者:
S. Winograd
通讯作者: S. Winograd
朱利叶斯.
DOI: --
发表时间: --
影响因子: 1.8
作者:
Carol M Dunckley
通讯作者: Carol M Dunckley
一种新的功耗感知 FPGA 设计指标
DOI: --
发表时间: 2015
影响因子: 1.9
作者:
Joshua Templin;J. Hamlet
通讯作者: J. Hamlet
DOI: --
发表时间: 2013
期刊: Fast Software Encryption Workshop
影响因子: --
作者:
A. Boldyreva;Jean Paul Degabriele;K. Paterson;Martijn Stam
通讯作者: Martijn Stam
关于用于认证和认证加密的分组密码的操作模式
DOI: --
发表时间: 2015
期刊: Cryptography and Communications
影响因子: --
作者:
D. Chakraborty;P. Sarkar
通讯作者: P. Sarkar