2012
DOI: 10.1007/978-3-642-34047-5_12
|View full text |Cite
|
Sign up to set email alerts
|

McOE: A Family of Almost Foolproof On-Line Authenticated Encryption Schemes

Abstract: Abstract. On-Line Authenticated Encryption (OAE) combines privacy with data integrity and is on-line computable. Most block cipher-based schemes for Authenticated Encryption can be run on-line and are provably secure against nonce-respecting adversaries. But they fail badly for more general adversaries. This is not a theoretical observation only -in practice, the reuse of nonces is a frequent issue 1 .In recent years, cryptographers developed misuse-resistant schemes for Authenticated Encryption. These guarant… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
102
0

Year Published

2014
2014
2021
2021

Publication Types

Select...
6
1

Relationship

0
7

Authors

Journals

citations
Cited by 79 publications
(102 citation statements)
references
References 34 publications
0
102
0
Order By: Relevance
“…For the cases when nonce values do repeat, none of these AE schemes provides any formal security guarantees. Indeed, all of these schemes, including the latest OTR, can be "attacked" under nonce repetition, as described by Fleischmann et al [12].…”
Section: Introductionmentioning
confidence: 99%
“…For the cases when nonce values do repeat, none of these AE schemes provides any formal security guarantees. Indeed, all of these schemes, including the latest OTR, can be "attacked" under nonce repetition, as described by Fleischmann et al [12].…”
Section: Introductionmentioning
confidence: 99%
“…For online arbitrary IV schemes, we demonstrate that PA1 security can be achieved only if the ciphertext is substantially longer than the plaintext, or the decryption is offline. We show that McOE-G [23] achieves PA1 if the plaintext is padded so that the ciphertext becomes twice as long. We also prove that APE [2], an online deterministic AE scheme with offline decryption, achieves PA1.…”
Section: Analysis Of Authenticated Encryption Schemesmentioning
confidence: 98%
“…Online Scheme PA1 PA2 Remark random CTR, CBC [35] nonce OCB [39] GCM [33], SpongeWrap [16] CCM [47] not online [41] arbitrary COPA [3] privacy up to prefix McOE-G [23] ′′ APE [2] ′′, backwards decryption SIV [40], BTM [27], HBS [28] privacy up to repetition Encode-then-Encipher [12] ′′, VIL SPRP, padding…”
Section: Typementioning
confidence: 99%
See 2 more Smart Citations