Paper 2025/1127
KIVR: Committing Authenticated Encryption Using Redundancy and Application to GCM, CCM, and More
Abstract
Constructing a committing authenticated encryption (AE) satisfying the CMT-4 security notion is an ongoing research challenge. We propose a new mode KIVR, a black-box conversion for adding the CMT-4 security to existing AEs. KIVR is a generalization of the Hash- then-Enc (HtE) [Bellare and Hoang, EUROCRYPT 2022] and uses a collision-resistant hash function to generate an initial value (or nonce) and a mask for redundant bits, in addition to a temporary key. We ob- tain a general bound r/2 + tag-col with r-bit redundancy for a large class of CTR-based AEs, where tag-col is the security against tag-collision at- tacks. Unlike HtE, the security of KIVR linearly increases with r, achiev- ing beyond-birthday-bound security. With a t-bit tag, tag-col lies 0 ≤ tag-col ≤ t/2 depending on the target AE. We set tag-col = 0 for GCM, GCM-SIV, and CCM, and the corresponding bound r/2 is tight for GCM and GCM-SIV. With CTR-HMAC, tag-col = t/2, and the bound (r + t)/2 is tight.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published elsewhere. Minor revision. ACNS 2024, The Third NIST Workshop on Block Cipher Modes of Operation 2023
- Keywords
- CCMGCMCommitting SecurityAE SecurityNonce-Based Key and IV
- Contact author(s)
-
Naito Yusuke @ ce mitsubishielectric co jp
yu sasaki sk @ hco ntt co jp
sugawara @ uec ac jp - History
- 2025-06-17: approved
- 2025-06-15: received
- See all versions
- Short URL
- https://ia.cr/2025/1127
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1127,
author = {Yusuke Naito and Yu Sasaki and Takeshi Sugawara},
title = {{KIVR}: Committing Authenticated Encryption Using Redundancy and Application to {GCM}, {CCM}, and More},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1127},
year = {2025},
url = {https://eprint.iacr.org/2025/1127}
}