[Resource Topic] 2019/892: CCM-SIV: Single-PRF Nonce-Misuse-Resistant Authenticated Encryption

Welcome to the resource topic for 2019/892

Title:
CCM-SIV: Single-PRF Nonce-Misuse-Resistant Authenticated Encryption

Authors: Patrick Kresmer, Alexander Zeh

Abstract:

We propose a new nonce-misuse-resistant authenticated encryption scheme, which instantiates the SIV paradigm of Rogaway and Shrimpton. In contrast to the GCM-SIV approach proposed by Gueron and Lindell, we do only use a single type of cryptographic primitive, which can be advantageous in restricted embedded devices. Furthermore, we use three independent and fixed subkeys derived from a single master key. Similar to the CCM mode, our scheme uses a combination of the CTR mode for the symmetric encryption and a MAC based on the CBC construction and is therefore called CCM-SIV. We provide a detailed security proof for our scheme. Furthermore, we outline its extension to a nonce-based key derivation as the AES-GCM-SIV approach.

ePrint: https://eprint.iacr.org/2019/892

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .