The Security and Performance of the Galois/Counter Mode (GCM) of Operation

The Security and Performance of the Galois/Counter Mode (GCM) of Operation
复制标题

DOI:
10.1007/978-3-540-30556-9_27
复制
发表时间:
2004-12
期刊:
--
影响因子:
--
通讯作者:
D. McGrew;J. Viega
D. McGrew;J. Viega
中科院分区:
其他
文献类型:
--
作者:
D. McGrew;J. Viega

文献摘要

被引文献

相似文献

最近引入的分组密码运算的伽罗瓦/计数器模式(GCM)使用基于二进制有限域中乘法的通用散列来提供加密和消息认证。通过使用一个现实的网络密码模块模型和来自互联网流量研究的经验数据,结合软件实验和硬件设计,我们分析了它的安全性和性能,表明它是高速分组网络最有效的操作模式。GCM有几个有用的特征:它可以接受任意长度的IV,可以充当独立的消息认证码(MAC),并且可以用作增量MAC。我们证明了GCM在具体安全的标准模型中是安全的,即使使用了这些功能。我们还考虑了它的几个重要的系统安全方面。
The recently introduced Galois/Counter Mode (GCM) of operation for block ciphers provides both encryption and message authentication, using universal hashing based on multiplication in a binary finite field. We analyze its security and performance, and show that it is the most efficient mode of operation for high speed packet networks, by using a realistic model of a network crypto module and empirical data from studies of Internet traffic in conjunction with software experiments and hardware designs. GCM has several useful features: it can accept IVs of arbitrary length, can act as a stand-alone message authentication code (MAC), and can be used as an incremental MAC. We show that GCM is secure in the standard model of concrete security, even when these features are used. We also consider several of its important system-security aspects.