Paper 2025/577

Making GCM Great Again: Toward Full Security and Longer Nonces

Woohyuk Chung, KAIST, Daejeon, Korea
Seongha Hwang, KAIST, Daejeon, Korea
Seongkwang Kim, Samsung SDS, Seoul, Korea
Byeonghak Lee, Samsung SDS, Seoul, Korea
Jooyoung Lee, KAIST, Daejeon, Korea
Abstract

The GCM authenticated encryption (AE) scheme is one of the most widely used AE schemes in the world, while it suffers from risk of nonce misuse, short message length per encryption and an insufficient level of security. The goal of this paper is to design new AE schemes achieving stronger provable security in the standard model and accepting longer nonces (or providing nonce misuse resistance), with the design rationale behind GCM. As a result, we propose two enhanced variants of GCM and GCM-SIV, dubbed eGCM and eGCM-SIV, respectively. eGCM and eGCM-SIV are built on top of a new CENC-type encryption mode, dubbed eCTR: using 2n-bit counters, eCTR enjoys beyond-birthday-bound security without significant loss of efficiency. eCTR is combined with an almost uniform and almost universal hash function, yielding a variable input-length variable output-length pseudorandom function, dubbed HteC. GCM and GCM-SIV are constructed using eCTR and HteC as building blocks. eGCM and eGCM-SIV accept nonces of arbitrary length, and provide almost the full security (namely, n-bit security when they are based on an n-bit block cipher) for a constant maximum input length, under the assumption that the underlying block cipher is a pseudorandom permutation (PRP). Their efficiency is also comparable to GCM in terms of the rate and the overall speed.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in EUROCRYPT 2025
Keywords
authenticated encryptionGCMbeyond-birthday-bound securityprovable security
Contact author(s)
hephaistus @ kaist ac kr
mathience98 @ kaist ac kr
sk39 kim @ samsung com
byghak lee @ samsung com
hicalf @ kaist ac kr
History
2025-04-01: approved
2025-03-30: received
See all versions
Short URL
https://ia.cr/2025/577
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/577,
      author = {Woohyuk Chung and Seongha Hwang and Seongkwang Kim and Byeonghak Lee and Jooyoung Lee},
      title = {Making {GCM} Great Again: Toward Full Security and Longer Nonces},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/577},
      year = {2025},
      url = {https://eprint.iacr.org/2025/577}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.