A Characterization of Authenticated-Encryption as a Form of Chosen-Ciphertext Security

Tom Shrimpton

Abstract: In this note we introduce a variation of the standard definition of chosen-ciphertext security, which we call IND-CCA3, and prove that IND-CCA3 is equivalent to authenticated-encryption.

Category / Keywords: secret-key cryptography / authenticated-encryption, definitions, chosen-ciphertext security

Date: received 18 Oct 2004

