Paper 2024/2053
HCTR+: An Optimally Secure TBC-based Accordion Mode
Abstract
The design of tweakable wide-block ciphers has advanced significantly over the past two decades. This evolution began with the wide-block cipher by Naor and Reingold. Since then, numerous constructions have been proposed, many of which are built on existing block ciphers and are secure up to the birthday bound for the total number of blocks queried. Although there has been a recent slowdown in the development of such ciphers, the latest NIST proposal for Accordion modes has reignited the interest and momentum in the design and analysis of these ciphers. Although new designs have emerged, their security often falls short of optimal (i.e., n-bit) security, where n is the output size of the primitive. In this direction, designing an efficient tweakable wide-block cipher with n-bit security seems to be an interesting research problem to the symmetric key research community. An optimally secure tweakable wide-block cipher mode can easily be turned into a misuse-resistant RUP secure authenticated encryption scheme with optimal security. This paper proposes HCTR+, which turns an n-bit tweakable block cipher (TBC) with n-bit tweak into a variable input length tweakable wide block cipher. Unlike tweakable HCTR, HCTR+ ensures n-bit security regardless of tweak repetitions. We also propose two TBC-based almost-xor-universal hash functions, named PHASH+ and ZHASH+, and use them as the underlying hash functions in the HCTR+ construction to create two TBC-based n-bit secure tweakable wide block cipher modes, PHCTR+ and ZHCTR+. Experimental results show that both PHCTR+ and ZHCTR+ exhibit excellent software performance when their underlying TBC is instantiated with Deoxys-BC-256.
Note: The older version of the paper had a security flaw, thanks to Takuto Takami, Takahiro Kaneko and Tetsu Iwata. We have corrected the flaw in this new version
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- A minor revision of an IACR publication in TOSC 2025
- DOI
- 10.46586/tosc.v2025.i3.183-229
- Keywords
- Tweakable wide block cipherTweakable block cipherAccordion modeProvable securityOptimal securityAESHCTR
- Contact author(s)
-
nilanjan datta @ tcgcrest org
avirocks dutta13 @ gmail com
shibam ghosh @ inria fr
elist @ posteo net
hrithik nandi 85 @ tcgcrest org - History
- 2026-03-23: last of 6 revisions
- 2024-12-20: received
- See all versions
- Short URL
- https://ia.cr/2024/2053
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2024/2053,
author = {Nilanjan Datta and Avijit Dutta and Shibam Ghosh and Eik List and Hrithik Nandi},
title = {{HCTR}+: An Optimally Secure {TBC}-based Accordion Mode},
howpublished = {Cryptology {ePrint} Archive, Paper 2024/2053},
year = {2024},
doi = {10.46586/tosc.v2025.i3.183-229},
url = {https://eprint.iacr.org/2024/2053}
}