Authenticated encryption: Relations among notions and analysis of the generic composition paradigm

Authenticated encryption: Relations among notions and analysis of the generic composition paradigm
复制标题

DOI:
10.1007/s00145-008-9026-x
复制
发表时间:
2008-10-01
影响因子:
3
通讯作者:
Namprempre, Chanathip
Namprempre, Chanathip
中科院分区:
计算机科学4区
文献类型:
--
作者:
Bellare, Mihir;Namprempre, Chanathip

文献摘要

被引文献

相似文献

经过身份验证的加密方案是一种对称加密方案,其目标是同时提供隐私和完整性。我们考虑了这种方案的两种可能的真实性概念,即明文的完整性和密文的完整性,并将它们与IND-CPA(所选明文攻击下的不可区分性)结合起来,通过提出所考虑的所有概念之间的含义和分离,将它们与标准的隐私概念IND-CCA和NM-CPA(所选密文攻击下的不可区分性和所选明文攻击下的不可延展性)联系起来。然后,我们分析了通过“通用组合”设计的经过身份验证的加密方案的安全性,这意味着使用给定的对称加密方案和给定的MAC进行黑箱操作。考虑了三种组合方法,即加密-MAC, MAC-然后加密和加密-然后MAC。对于这些和每个安全概念,我们指出结果方案是否满足所讨论的概念,假设给定的对称加密方案对选择明文攻击是安全的,并且给定的MAC在选择消息攻击下是不可伪造的。我们为答案是“是”的情况提供证明,并为答案是“否”的情况提供反例。
An authenticated encryption scheme is a symmetric encryption scheme whose goal is to provide both privacy and integrity. We consider two possible notions of authenticity for such schemes, namely integrity of plaintexts and integrity of ciphertexts, and relate them, when coupled with IND-CPA (indistinguishability under chosen-plaintext attack), to the standard notions of privacy IND-CCA and NM-CPA (indistinguishability under chosen-ciphertext attack and nonmalleability under chosen-plaintext attack) by presenting implications and separations between all notions considered. We then analyze the security of authenticated encryption schemes designed by "generic composition," meaning making black-box use of a given symmetric encryption scheme and a given MAC. Three composition methods are considered, namely Encrypt-and-MAC, MAC-then-encrypt, and Encrypt-then-MAC. For each of these and for each notion of security, we indicate whether or not the resulting scheme meets the notion in question assuming that the given symmetric encryption scheme is secure against chosen-plaintext attack and the given MAC is unforgeable under chosen-message attack. We provide proofs for the cases where the answer is "yes" and counter-examples for the cases where the answer is "no.".