Lightweight Authenticated Encryption Mode Suitable for Threshold Implementation
Yusuke Naito, Yu Sasaki, Takeshi Sugawara
摘要
This paper proposes tweakable block cipher (TBC) based modes minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus and minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFBω that are efficient in threshold implementations (TI). Let t be an algebraic degree of a target function, e.g. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentt=1 (resp. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentt>1) for linear (resp. non-linear) function. The d-th order TI encodes the internal state into minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentdt+1 shares. Hence, the area size increases proportionally to the number of shares. This implies that TBC based modes can be smaller than block cipher (BC) based modes in TI because TBC requires s-bit block to ensure s-bit security, e.g. PFB and Romulus, while BC requires 2s-bit block. However, even with those TBC based modes, the minimum we can reach is 3 shares of s-bit state with minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentt=2 and the first-order TI (minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentd=1). Our first design minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus aims to break the barrier of the 3s-bit state in TI. The block size of an underlying TBC is s/2 bits and the output of TBC is linearly expanded to s bits. This expanded state requires only 2 shares in the first-order TI, which makes the total state size 2.5s bits. We also provide rigorous security proof of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus. Our second design minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFBω further increases a parameter minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentω: a ratio of the security level s to the block size of an underlying TBC. We prove security of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFBω for any minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentω under some assumptions for an underlying TBC and for parameters used to update a state. Next, we show a concrete instantiation of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus for 128-bit security. It requires a TBC with 64-bit block, 128-bit key and 128-bit tweak, while no existing TBC can support it. We design a new TBC by extending SKINNY and provide basic security evaluation. Finally, we give hardware benchmarks of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus in the first-order TI to show that TI of minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentPFB_Plus is smaller than that of PFB by more than one thousand gates and is the smallest within the schemes having 128-bit security.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper2
- Secret Can Be Public: Low-Memory AEAD Mode for High-Order MaskingYusuke Naito, Yu Sasaki, Takeshi SugawaraCRYPTO 2022 · 被引用 13 次
- Let's Go Eevee! A Friendly and Suitable Family of AEAD Modes for IoT-to-Cloud Secure ComputationAmit Singh Bhati, Erik Pohle, Aysajan Abidin, Elena Andreeva 等CCS 2023 · 被引用 8 次
相关 Paper
- TNT: How to Tweak a Block CipherZhenzhen Bao, Chun Guo, Jian Guo, Ling SongEUROCRYPT 2020 · 被引用 20 次
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos 等EUROCRYPT 2024 · 被引用 4 次
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 被引用 4 次
- BTX and SimpleBTE: Efficient Batched Threshold EncryptionAmit Agarwal, Sourav Das, Babak Poorebrahim Gilkalaye, Guru-Vamsi Policharla 等CCS 2026
- Tweakable Permutation-Based Luby-Rackoff ConstructionsBishwajit Chakraborty, Abishanka SahaCRYPTO 2025
