Cryptology ePrint Archive: Report 2019/123

Security of Multilinear Galois Mode (MGM)

Liliya Akhmetzyanova and Evgeny Alekseev and Grigory Karpunin and Vladislav Nozdrunov

Abstract: In this paper we analyze the new AEAD mode called the Multilinear Galois Mode (MGM) originally proposed in CTCrypt 2017. This mode is currently considered in the Russian Standardization system as the main contender to be adopted as a standard AEAD mode. The analysis of the MGM mode was carried out in the paradigm of provable security, in other words, lower security bounds were obtained for the Privacy and Authenticity notions. These bounds show that the privacy and authenticity of this mode is provably guaranteed (under security of the used block cipher) up to the birthday paradox bound.

Category / Keywords: secret-key cryptography / AEAD, privacy, integrity, provable security

Date: received 7 Feb 2019

Contact author: lah at cryptopro ru

Version: 20190213:034128 (All versions of this report)

