[Resource Topic] 2017/708: Reconsidering the Security Bound of AES-GCM-SIV

Welcome to the resource topic for 2017/708

Title:
Reconsidering the Security Bound of AES-GCM-SIV

Authors: Tetsu Iwata, Yannick Seurin

Abstract:

We make a number of remarks about the AES-GCM-SIV nonce-misuse resistant authenticated encryption scheme currently considered for standardization by the Crypto Forum Research Group (CFRG). First, we point out that the security analysis proposed in the ePrint report 2017/168 is incorrect, leading to overly optimistic security claims. We correct the bound and re-assess the security guarantees offered by the scheme for various parameters. Second, we suggest a simple modification to the key derivation function which would improve the security of the scheme with virtually no efficiency penalty.

ePrint: https://eprint.iacr.org/2017/708

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .