Lune

EUROCRYPT2020顶会

Lightweight Authenticated Encryption Mode Suitable for Threshold Implementation

Yusuke Naito, Yu Sasaki, Takeshi Sugawara

2020年份
33被引次数
2顶会引用

摘要

This paper proposes tweakable block cipher (TBC) based modes minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFB_Plus\mathsf {PFB\_Plus}documentPFB_Plus and minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFBω\mathsf {PFB}\omega documentPFBω that are efficient in threshold implementations (TI). Let t be an algebraic degree of a target function, e.g. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentt=1t=1documentt=1 (resp. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentt>1t>1documentt>1) for linear (resp. non-linear) function. The d-th order TI encodes the internal state into minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdt+1d t + 1documentdt+1 shares. Hence, the area size increases proportionally to the number of shares. This implies that TBC based modes can be smaller than block cipher (BC) based modes in TI because TBC requires s-bit block to ensure s-bit security, e.g. PFB and Romulus, while BC requires 2s-bit block. However, even with those TBC based modes, the minimum we can reach is 3 shares of s-bit state with minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentt=2t=2documentt=2 and the first-order TI (minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentd=1d=1documentd=1). Our first design minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFB_Plus\mathsf {PFB\_Plus}documentPFB_Plus aims to break the barrier of the 3s-bit state in TI. The block size of an underlying TBC is s/2 bits and the output of TBC is linearly expanded to s bits. This expanded state requires only 2 shares in the first-order TI, which makes the total state size 2.5s bits. We also provide rigorous security proof of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFB_Plus\mathsf {PFB\_Plus}documentPFB_Plus. Our second design minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFBω\mathsf {PFB}\omega documentPFBω further increases a parameter minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentω\omega documentω: a ratio of the security level s to the block size of an underlying TBC. We prove security of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFBω\mathsf {PFB}\omega documentPFBω for any minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentω\omega documentω under some assumptions for an underlying TBC and for parameters used to update a state. Next, we show a concrete instantiation of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFB_Plus\mathsf {PFB\_Plus}documentPFB_Plus for 128-bit security. It requires a TBC with 64-bit block, 128-bit key and 128-bit tweak, while no existing TBC can support it. We design a new TBC by extending SKINNY and provide basic security evaluation. Finally, we give hardware benchmarks of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFB_Plus\mathsf {PFB\_Plus}documentPFB_Plus in the first-order TI to show that TI of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentPFB_Plus\mathsf {PFB\_Plus}documentPFB_Plus is smaller than that of PFB by more than one thousand gates and is the smallest within the schemes having 128-bit security.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper2

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖