Damaging, simplifying, and salvaging p-OMD

Tomer Ashur, B.J.M. Mennink

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageAcademicpeer review

14 Downloads (Pure)

Samenvatting

One of the submissions to the CAESAR competition for the design of a new authenticated encryption scheme is Offset Merkle-Damgård (OMD). At FSE 2015, Reyhanitabar et al. introduced p-OMD, an improvement of OMD that processes the associated data almost for free. As an extra benefit, p-OMD was claimed to offer integrity against nonce-misusing adversaries, a property that OMD does not have. In this work we show how a nonce-misusing adversary can forge a message for the original p-OMD using only 3 queries (including the forgery). As a second contribution, we generalize and simplify p-OMD. This is done via the introduction of the authenticated encryption scheme Spoed. The most important difference is the usage of a generalized padding function GPAD, which neatly eliminates the need for a case distinction in the design specification and therewith allows for a significantly shorter description of the scheme and a better security bound. Finally, we introduce the authenticated encryption scheme Spoednic, a variant of Spoed providing authenticity against a nonce-misusing adversary at a modest price.
Originele taal-2Engels
TitelInternational Conference on Information Security
RedacteurenM. Bishop, A. Nascimento
Plaats van productieCham
UitgeverijSpringer
Pagina's73-92
ISBN van elektronische versie978-3-319-45871-7
ISBN van geprinte versie978-3-319-45870-0
DOI's
StatusGepubliceerd - 2016
Extern gepubliceerdJa

Publicatie series

NaamLecture Notes in Computer Science
UitgeverijSpringerLink
Volume9866

Vingerafdruk

Duik in de onderzoeksthema's van 'Damaging, simplifying, and salvaging p-OMD'. Samen vormen ze een unieke vingerafdruk.

Citeer dit