首页> 外文会议>International Conference on the Theory and Application of Cryptology and Information Security >Beyond 2~(c/2) Security in Sponge-Based Authenticated Encryption Modes
【24h】

Beyond 2~(c/2) Security in Sponge-Based Authenticated Encryption Modes

机译:超越基于海绵的经过验证的加密模式的2〜(C / 2)安全性

获取原文

摘要

The Sponge function is known to achieve 2~(c/2) security, where c is its capacity. This bound was carried over to keyed variants of the function, such as SpongeWrap, to achieve a min{2~(c/2), 2~κ} security bound, with κ the key length. Similarly, many CAESAR competition submissions are designed to comply with the classical 2~(c/2) security bound. We show that Sponge-based constructions for authenticated encryption can achieve the significantly higher bound of min {2~(b/2),2~c,2~κ} asymptotically, with b > c the permutation size, by proving that the CAESAR submission NORX achieves this bound. Furthermore, we show how to apply the proof to five other Sponge-based CAESAR submissions: Ascon, CBEAM/STRIBOB, ICEPOLE, Keyak, and two out of the three PRIMATEs. A direct application of the result shows that the parameter choices of these submissions are overly conservative. Simple tweaks render the schemes considerably more efficient without sacrificing security. For instance, NORX64 can increase its rate and decrease its capacity by 128 bits and Ascon-128 can encrypt three times as fast, both without affecting the security level of their underlying modes in the ideal permutation model.
机译:已知海绵函数实现2〜(C / 2)安全性,其中C是其容量。这种界限被携带到函数的钥匙变体,例如海绵包装,以实现最小的{2〜(C / 2),2〜κ}安全绑定,κ关键长度。同样,许多凯撒竞争提交旨在遵守古典2〜(C / 2)安全绑定。我们表明,用于认证的加密基于海绵的结构可以实现显著更高结合分钟的{2〜(B / 2),2〜C,2〜κ}渐近,与B> C的置换大小,通过证明CAESAR提交诺克斯实现了这一界限。此外,我们展示了如何将证明应用于五个基于海绵的凯撒提交:ASCON,CBEAM / Stribob,IcePole,Keyak和三个灵长类动物中的两个。直接应用结果表明,这些提交的参数选择过于保守。简单的调整渲染方案在不牺牲安全性的情况下更有效。例如,NORX64可以增加其速率和128位和ASCON-128降低,而不影响在理想置换模型及其基本模式的安全级别加密快三倍,无论是它的容量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号