TNT: How to Tweak a Block Cipher
Zhenzhen Bao, Chun Guo, Jian Guo, Ling Song
摘要
In this paper, we propose Tweak-aNd-Tweak (minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT for short) mode, which builds a tweakable block cipher from three independent block ciphers. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT handles the tweak input by simply XOR-ing the unmodified tweak into the internal state of block ciphers twice. Due to its simplicity, minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT can also be viewed as a way of turning a block cipher into a tweakable block cipher by dividing the block cipher into three chunks, and adding the tweak at the two cutting points only. minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT is proven to be of beyond-birthday-bound minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument22n/3 security, under the assumption that the three chunks are independent secure n-bit SPRPs. It clearly brings minimum possible overhead to both software and hardware implementations. To demonstrate this, an instantiation named TNT-AES with minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument6, minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument6, minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocument6 rounds of AES as the underlying block ciphers is proposed. Besides the inherent proven security bound and tweak-independent rekeying feature of the minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt documentdocumentTNT mode, the performance of TNT-AES is comparable with all existing TBCs designed through modular methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Truncated Boomerang Attacks and Application to AES-Based CiphersAugustin Bariant, Gaëtan LeurentEUROCRYPT 2023 · 被引用 29 次
- Partial Sums Meet FFT: Improved Attack on 6-Round AESOrr Dunkelman, Shibam Ghosh, Nathan Keller, Gaëtan Leurent 等EUROCRYPT 2024 · 被引用 10 次
它引用的顶会 Paper1
相关 Paper
- Lightweight Authenticated Encryption Mode Suitable for Threshold ImplementationYusuke Naito, Yu Sasaki, Takeshi SugawaraEUROCRYPT 2020 · 被引用 33 次
- Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW ParadigmAshwin Jha, Mustafa Khairallah, Mridul Nandi, Abishanka SahaEUROCRYPT 2024 · 被引用 7 次
- Efficient Instances of Docked Double Decker with AES, and Application to Authenticated EncryptionChristoph Dobraunig, Krystian Matusiewicz, Bart Mennink, Alexander TereschenkoEUROCRYPT 2025 · 被引用 4 次
- Secret Can Be Public: Low-Memory AEAD Mode for High-Order MaskingYusuke Naito, Yu Sasaki, Takeshi SugawaraCRYPTO 2022 · 被引用 13 次
- How to Recover the Full Plaintext of XCBPeng Wang, Shuping Mao, Ruozhou Xu, Jiwu Jing 等CRYPTO 2025 · 被引用 3 次
