Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. Online Authenticated-Encryption and its Nonce-Reuse Misuse-Resistance
 
conference paper

Online Authenticated-Encryption and its Nonce-Reuse Misuse-Resistance

Hoang, Viet Tung
•
Reyhanitabar, Reza  
•
Rogaway, Phillip
Show more
2015
Advances in Cryptology - CRYPTO 2015 - 35th Annual Cryptology Conference, Proceedings, Part I
CRYPTO 2015

A definition of online authenticated-encryption (OAE), call it OAE1, was given by Fleischmann, Forler, and Lucks (2012). It has become a popular definitional target because, despite allowing encryption to be online, security is supposed to be maintained even if nonces get reused. We argue that this expectation is effectively wrong. OAE1 security has also been claimed to capture best-possible security for any online-AE scheme. We claim that this understanding is wrong, too. So motivated, we redefine OAE-security, providing a radically different formulation, OAE2. The new notion effectively does capture best-possible security for a user’s choice of plaintext segmentation and ciphertext expansion. It is achievable by simple techniques from standard tools. Yet even for OAE2, nonce-reuse can still be devastating. The picture to emerge is that no OAE definition can meaningfully tolerate nonce-reuse, but, at the same time, OAE security ought never have been understood to turn on this question.

  • Details
  • Metrics
Type
conference paper
DOI
10.1007/978-3-662-47989-6_24
Web of Science ID

WOS:000364183000024

Author(s)
Hoang, Viet Tung
Reyhanitabar, Reza  
Rogaway, Phillip
Vizár, Damian  
Date Issued

2015

Publisher

Springer

Publisher place

Berlin

Published in
Advances in Cryptology - CRYPTO 2015 - 35th Annual Cryptology Conference, Proceedings, Part I
ISBN of the book

978-3-662-47989-6

978-3-662-47988-9

Total of pages

25

Series title/Series vol.

Lecture Notes in Computer Science; 9215

Start page

493

End page

517

Subjects

Authenticated encryption

•

CAESAR competition

•

Misuse resistance

•

Nonce reuse

•

Online AE

•

Symmetric encryption

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LASEC  
Event nameEvent placeEvent date
CRYPTO 2015

Santa Barbara, CA, USA

August 16-20, 2015

Available on Infoscience
August 31, 2015
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/117499
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés