Lightweight Authenticated Encryption Mode Suitable for Threshold Implementation
Yusuke Naito, Yu Sasaki, Takeshi Sugawara
Abstract
This paper proposes tweakable block cipher (TBC) based modes minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus and minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFBω that are efficient in threshold implementations (TI). Let t be an algebraic degree of a target function, e.g. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentt=1 (resp. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentt>1) for linear (resp. non-linear) function. The d-th order TI encodes the internal state into minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentdt+1 shares. Hence, the area size increases proportionally to the number of shares. This implies that TBC based modes can be smaller than block cipher (BC) based modes in TI because TBC requires s-bit block to ensure s-bit security, e.g. PFB and Romulus, while BC requires 2s-bit block. However, even with those TBC based modes, the minimum we can reach is 3 shares of s-bit state with minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentt=2 and the first-order TI (minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentd=1). Our first design minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus aims to break the barrier of the 3s-bit state in TI. The block size of an underlying TBC is s/2 bits and the output of TBC is linearly expanded to s bits. This expanded state requires only 2 shares in the first-order TI, which makes the total state size 2.5s bits. We also provide rigorous security proof of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus. Our second design minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFBω further increases a parameter minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentω: a ratio of the security level s to the block size of an underlying TBC. We prove security of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFBω for any minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentω under some assumptions for an underlying TBC and for parameters used to update a state. Next, we show a concrete instantiation of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus for 128-bit security. It requires a TBC with 64-bit block, 128-bit key and 128-bit tweak, while no existing TBC can support it. We design a new TBC by extending SKINNY and provide basic security evaluation. Finally, we give hardware benchmarks of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus in the first-order TI to show that TI of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus is smaller than that of PFB by more than one thousand gates and is the smallest within the schemes having 128-bit security.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Secret Can Be Public: Low-Memory AEAD Mode for High-Order MaskingYusuke Naito, Yu Sasaki, Takeshi SugawaraCRYPTO 2022 · 13 citations
- Let's Go Eevee! A Friendly and Suitable Family of AEAD Modes for IoT-to-Cloud Secure ComputationAmit Singh Bhati, Erik Pohle, Aysajan Abidin, Elena Andreeva et al.CCS 2023 · 8 citations
Related papers
- TNT: How to Tweak a Block CipherZhenzhen Bao, Chun Guo, Jian Guo, Ling SongEUROCRYPT 2020 · 20 citations
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos et al.EUROCRYPT 2024 · 4 citations
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 4 citations
- BTX and SimpleBTE: Efficient Batched Threshold EncryptionAmit Agarwal, Sourav Das, Babak Poorebrahim Gilkalaye, Guru-Vamsi Policharla et al.CCS 2026
- Tweakable Permutation-Based Luby-Rackoff ConstructionsBishwajit Chakraborty, Abishanka SahaCRYPTO 2025
