: A Domain-Extended Committing BBB PRF for Strengthening GCM
Ritam Bhaumik, Jean Paul Degabriele, Chandranan Dhar
Abstract
We consider the problem of constructing efficient committing pseudorandom functions with Beyond-Birthday-Bound (BBB) security from blockciphers. More specifically, we are interested in expanding pseudorandom functions (PRF) whose domain is roughly twice that of the underlying blockcipher. The main motivation behind our work is to construct an AES-based key derivation function (KDF) that can be combined with GCM in order to improve its security bound, accommodate larger nonces that can be generated randomly without risking collisions, and make it a committing AEAD scheme. NIST has recently announced a pre-draft call for comments to standardise AEAD schemes that can encrypt larger amounts of data and admit larger nonces. The call lists two approaches. The first is to define an analogue of GCM using a 256-bit blockcipher, and the second is based on a recent proposal by Gueron, to extend GCM with a key derivation function (KDF) called to increase its security. The latter has clear benefits in terms of backwards compatibility and is likely to be the preferred interim solution. Moreover, - is already deployed in production at Meta. is essentially a BBB-secure expanding weak pseudorandom function with a domain size of 192 bits realised from AES. We here propose an alternative AES-based KDF called with comparable efficiency but stronger provable security guarantees. Specifically, is a full PRF, whereas is only a weak PRF, which allows us to prove the - composition secure as an AEAD scheme. Our most technically challenging result is to show that is committing, whereas claims this property without proof. Finally, in contrast to and other alternatives, can be safely used with arbitrary (non-random) nonces and remains committing even when the nonce is not included as part of the ciphertext.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a9e0eee2-5a28-412e-856f-486940eb3a82Related papers
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 11 citations
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 4 citations
- Towards Optimally Secure Deterministic Authenticated Encryption SchemesYu Long Chen, Avijit Dutta, Ashwin Jha, Mridul NandiEUROCRYPT 2025 · 2 citations
- Security of Streaming Encryption in Google's Tink LibraryViet Tung Hoang, Yaobin ShenCCS 2020
- Better Bounds for Block Cipher Modes of Operation via Nonce-Based Key DerivationShay Gueron, Yehuda LindellCCS 2017 · 38 citations
