Authenticated Encryption in the Face of Protocol and Side Channel Leakage

Guy Barwell, Daniel P. Martin, Elisabeth Oswald, and Martijn Stam


Authenticated encryption schemes in practice have to be robust against adversaries that have access to various types of leakage, for instance decryption leakage on invalid ciphertexts (protocol leakage), or leakage on the underlying primitives (side channel leakage). This work includes several novel contributions: we augment the notion of nonce-base authenticated encryption with the notion of continuous leakage and we prove composition results in the face of protocol and side channel leakage. Moreover, we show how to achieve authenticated encryption that is simultaneously both misuse resistant and leakage resilient, based on a sufficiently leakage resilient PRF, and finally we propose a concrete, pairing-based, instantiation of the latter.

Note: Updated full version of the corresponding Asiacrypt'17 author's version

Secret-key cryptography
Published by the IACR in ASIACRYPT 2017
provable securityauthenticated encryptiongeneric compositionleakage resiliencerobustness
martijn stam @ bristol ac uk
2017-09-13: last of 3 revisions
2017-01-31: received
