Insecurity of RCB: Leakage-Resilient Authenticated Encryption

Farzaneh abed and Francesco Berti and Stefan Lucks

Abstract: Leakage-resilient cryptography is about security in the pres- ence of leakage from side-channels. In this paper, we present several issues of the RCB block cipher mode. Agrawal et al [2] proposed recently RCB as a leakage-resilient authenticated encryption (AE) scheme. Our main result is that RCB fails to provide authenticity, even in the absence of leakage.

Category / Keywords: authenticated encryption, leakage-resilience, block cipher, attack

