跳到主要导航 跳到搜索 跳到主要内容

Efficient side-channel secure message authentication with better bounds

  • Chun Guo
  • , François Xavier Standaert
  • , Weijia Wang
  • , Yu Yu
  • Shandong University
  • Université catholique de Louvain
  • Shanghai Jiao Tong University
  • State Key Laboratory of Cryptology

科研成果: 期刊稿件文章同行评审

摘要

We investigate constructing message authentication schemes from symmetric cryptographic primitives, with the goal of achieving security when most intermediate values during tag computation and verification are leaked (i.e., mode-level leakage-resilience). Existing efficient proposals typically follow the plain Hash-then-MAC paradigm T = TGenK(H(M)). When the domain of the MAC function TGenK is {0, 1}128, e.g., when instantiated with the AES, forgery is possible within time 264 and data complexity 1. To dismiss such cheap attacks, we propose two modes: LRW1-based Hash-then-MAC (LRWHM) that is built upon the LRW1 tweakable blockcipher of Liskov, Rivest, and Wagner, and Rekeying Hash-then-MAC (RHM) that employs internal rekeying. Built upon secure AES implementations, LRWHM is provably secure up to (beyond-birthday) 278.3 time complexity, while RHM is provably secure up to 2121 time. Thus in practice, their main security threat is expected to be side-channel key recovery attacks against the AES implementations. Finally, we benchmark the performance of instances of our modes based on the AES and SHA3 and confirm their efficiency.

源语言英语
页(从-至)23-53
页数31
期刊IACR Transactions on Symmetric Cryptology
2019
4
DOI
出版状态已出版 - 2019
已对外发布

指纹

探究 'Efficient side-channel secure message authentication with better bounds' 的科研主题。它们共同构成独一无二的指纹。

引用此