|
sMGM: parameterizable AEAD mode
L. R. Akhmetzyanova, E. K. Alekseev, A. A. Babueva, A. A. Bozhko, S. V. Smyshlyaev CryptoPro LLC, Moscow
Abstract:
The paper introduces a new AEAD mode called sMGM (strong Multilinear Galois Mode). The proposed construction can be treated as an extension of the Russian standardized MGM mode and its modification MGM2 mode presented at the CTCrypt'21 conference. The distinctive feature of the new mode is that it provides an interface allowing to choose specific security properties required for a certain application case. Namely, the mode has additional parameters allowing to switch on/off misuse-resistance or re-keying mechanisms.
The sMGM mode consists of two main «building blocks» that are a CTR-style gamma generation function with incorporated re-keying and a multilinear function that lies in the core of the original MGM mode. Different ways of using these functions leads to achieving different sets of security properties. This approach to the construction of parameterizable AEAD mode allows to reduce the code size which can be crucial for constrained devices.
We provide security bounds for the proposed mode. We focus on proving misuse-resistance of the sMGM mode, since the standard security properties were already analyzed during development of the original MGM and MGM2 modes.
Key words:
MGM, MGM2, AEAD mode, security notion, security bounds, nonce-misuse, misuse-resistant, SIV, re-keying.
Received 02.IX.2022
Citation:
L. R. Akhmetzyanova, E. K. Alekseev, A. A. Babueva, A. A. Bozhko, S. V. Smyshlyaev, “sMGM: parameterizable AEAD mode”, Mat. Vopr. Kriptogr., 14:2 (2023), 7–24
Linking options:
https://www.mathnet.ru/eng/mvk435https://doi.org/10.4213/mvk435 https://www.mathnet.ru/eng/mvk/v14/i2/p7
|
Statistics & downloads: |
Abstract page: | 179 | Full-text PDF : | 65 | References: | 30 | First page: | 2 |
|