Paper 2025/1127

KIVR: Committing Authenticated Encryption Using Redundancy and Application to GCM, CCM, and More

Yusuke Naito, Mitsubishi Electric Corporation
Yu Sasaki, NTT Social Informatics Laboratories and Associate of National Institute of Standards and Technology
Takeshi Sugawara, The University of Electro-Communications
Abstract

Constructing a committing authenticated encryption (AE) satisfying the CMT-4 security notion is an ongoing research challenge. We propose a new mode KIVR, a black-box conversion for adding the CMT-4 security to existing AEs. KIVR is a generalization of the Hash- then-Enc (HtE) [Bellare and Hoang, EUROCRYPT 2022] and uses a collision-resistant hash function to generate an initial value (or nonce) and a mask for redundant bits, in addition to a temporary key. We ob- tain a general bound r/2 + tag-col with r-bit redundancy for a large class of CTR-based AEs, where tag-col is the security against tag-collision at- tacks. Unlike HtE, the security of KIVR linearly increases with r, achiev- ing beyond-birthday-bound security. With a t-bit tag, tag-col lies 0 ≤ tag-col ≤ t/2 depending on the target AE. We set tag-col = 0 for GCM, GCM-SIV, and CCM, and the corresponding bound r/2 is tight for GCM and GCM-SIV. With CTR-HMAC, tag-col = t/2, and the bound (r + t)/2 is tight.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published elsewhere. Minor revision. ACNS 2024, The Third NIST Workshop on Block Cipher Modes of Operation 2023
Keywords
CCMGCMCommitting SecurityAE SecurityNonce-Based Key and IV
Contact author(s)
Naito Yusuke @ ce mitsubishielectric co jp
yu sasaki sk @ hco ntt co jp
sugawara @ uec ac jp
History
2025-06-17: approved
2025-06-15: received
See all versions
Short URL
https://ia.cr/2025/1127
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1127,
      author = {Yusuke Naito and Yu Sasaki and Takeshi Sugawara},
      title = {{KIVR}: Committing Authenticated Encryption Using Redundancy and Application to {GCM}, {CCM}, and More},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1127},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1127}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.