TNT: How to Tweak a Block Cipher
Zhenzhen Bao, Chun Guo, Jian Guo, Ling Song
Abstract
In this paper, we propose Tweak-aNd-Tweak (minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT for short) mode, which builds a tweakable block cipher from three independent block ciphers. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT handles the tweak input by simply XOR-ing the unmodified tweak into the internal state of block ciphers twice. Due to its simplicity, minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT can also be viewed as a way of turning a block cipher into a tweakable block cipher by dividing the block cipher into three chunks, and adding the tweak at the two cutting points only. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT is proven to be of beyond-birthday-bound minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument22n/3 security, under the assumption that the three chunks are independent secure n-bit SPRPs. It clearly brings minimum possible overhead to both software and hardware implementations. To demonstrate this, an instantiation named TNT-AES with minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument6, minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument6, minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument6 rounds of AES as the underlying block ciphers is proposed. Besides the inherent proven security bound and tweak-independent rekeying feature of the minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT mode, the performance of TNT-AES is comparable with all existing TBCs designed through modular methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aa362286-2119-4fcc-bccc-159841642df1Cited by top-tier papers2
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 29 citations
- Partial Sums Meet FFT: Improved Attack on 6-Round AESOrr Dunkelman, Shibam Ghosh, Nathan Keller, Gaëtan Leurent et al.EUROCRYPT 2024 · 10 citations
Builds on1
Related papers
- Lightweight Authenticated Encryption Mode Suitable for Threshold ImplementationYusuke Naito, Yu Sasaki, Takeshi SugawaraEUROCRYPT 2020 · 33 citations
- Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW ParadigmAshwin Jha, Mustafa Khairallah, Mridul Nandi, Abishanka SahaEUROCRYPT 2024 · 7 citations
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 4 citations
- Secret Can Be Public: Low-Memory AEAD Mode for High-Order MaskingYusuke Naito, Yu Sasaki, Takeshi SugawaraCRYPTO 2022 · 13 citations
- How to Recover the Full Plaintext of XCBPeng Wang, Shuping Mao, Ruozhou Xu, Jiwu Jing et al.CRYPTO 2025 · 3 citations
