Efficient Schemes for Committing Authenticated Encryption
Mihir Bellare, Viet Tung Hoang
2022Year
54Citations
7Top-tier citations
Abstract
This paper provides efficient authenticated-encryption (AE) schemes in which a ciphertext is a commitment to the key. These are extended, at minimal additional cost, to schemes where the ciphertext is a commitment to all encryption inputs, meaning key, nonce, associated data and message. Our primary schemes are modifications of GCM (for basic, unique-nonce AE security) and AES-GCM-SIV (for misuse-resistant AE security) and add both forms of commitment without any increase in ciphertext size. We also give more generic, but somewhat more costly, solutions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- When Messages Are Keys: Is HMAC a Dual-PRF?Matilda Backendal, Mihir Bellare, Felix Günther, Matteo ScarlataCRYPTO 2023 · 14 citations
- Multi-Stage Group Key Distribution and PAKEs: Securing Zoom Groups against Malicious Servers without New Security ElementsCas Cremers, Eyal Ronen, Mang ZhaoS&P 2024 · 2 citations
- Automated Analysis of Protocols that use Authenticated Encryption: How Subtle AEAD Differences can impact Protocol SecurityCas Cremers, Alexander Dax, Charlie Jacomme, Mang ZhaoUSENIX Security 2023
- Onion Franking: Abuse Reports for Mix-Based Private MessagingMatthew Gregoire, Margaret Pierce, Saba EskandarianNDSS 2025
- Encrypted Access Logging for Online Accounts: Device Attributions without Device TrackingCarolina Ortega Pérez, Alaa DaffallaUSENIX Security 2025
Builds on4
- Partitioning Oracle AttacksJulia Len, Paul Grubbs, Thomas RistenpartUSENIX Security 2021 · 57 citations
- The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce RandomizationViet Tung Hoang, Stefano Tessaro, Aishwarya ThiruvengadamCCS 2018 · 39 citations
- Better Bounds for Block Cipher Modes of Operation via Nonce-Based Key DerivationShay Gueron, Yehuda LindellCCS 2017 · 38 citations
- How to Abuse and Fix Authenticated Encryption Without Key CommitmentAnge Albertini, Thai Duong, Shay Gueron, Stefan Kölbl et al.USENIX Security 2022
Related papers
- Making GCM Great Again: Toward Full Security and Longer NoncesWoohyuk Chung, Seongha Hwang, Seongkwang Kim, Byeonghak Lee et al.EUROCRYPT 2025 · 2 citations
- Succinctly-Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangCRYPTO 2024 · 11 citations
- Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and MoreSanketh Menda, Julia Len, Paul Grubbs, Thomas RistenpartEUROCRYPT 2023 · 17 citations
- Committing Authenticated Encryption: Generic Transforms with Hash FunctionsShan Chen, Vukasin KaradzicEUROCRYPT 2025 · 3 citations
- A Robust Variant of ChaCha20-Poly1305Tim Beyne, Yu Long Chen, Michiel VerbauwhedeCRYPTO 2026 · 1 citation
