Paper 2020/731
The Exact Security of PMAC with Three Powering-Up Masks
Yusuke Naito
Abstract
PMAC is a rate-1, parallelizable, block-cipher-based message authentication code (MAC), proposed by Black and Rogaway (EUROCRYPT 2002). Improving the security bound is a main research topic for PMAC. In particular, showing a tight bound is the primary goal of the research, since Luykx et al.'s paper (EUROCRYPT 2016). Regarding the pseudo-random-function (PRF) security of PMAC, a collision of the hash function, or the difference between a random permutation and a random function offers the lower bound
Note: This paper is an update version of our ToSC paper (The Exact Security of PMAC with Two Powering-Up Masks, ToSC 2019 Issue 2). In the ToSC paper, we considered PMAC with two powering-up masks, and claimed that the PMAC has the tight security bounds O(q^2/2^n) for PRF-security and O(q_m^2/2^n+q_v/2^n) for MAC-security. However, Nandi et al. pointed out a bug of the proofs. Hence, we change the masking scheme with three powering-up masks, and prove that the PMAC has the tight security bounds.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- A major revision of an IACR publication in FSE 2020
- Keywords
- PMACpowering-upmessage-length influencePRF-securityMAC-securitytight security
- Contact author(s)
- Naito Yusuke @ ce mitsubishielectric co jp
- History
- 2020-06-17: received
- Short URL
- https://ia.cr/2020/731
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2020/731, author = {Yusuke Naito}, title = {The Exact Security of {PMAC} with Three Powering-Up Masks}, howpublished = {Cryptology {ePrint} Archive, Paper 2020/731}, year = {2020}, url = {https://eprint.iacr.org/2020/731} }