Paper 2025/953

Tight Multi-User Security of CCM and Enhancement by Tag-Based Key Derivation Applied to GCM and CCM

Yusuke Naito, Mitsubishi Electric Corporation
Yu Sasaki, NTT Social Informatics Laboratories and Associate of National Institute of Standards and Technology
Takeshi Sugawara, The University of Electro-Communications
Abstract

$\textsf{GCM}$ and $\textsf{CCM}$ are block cipher (BC) based authenticated encryption modes. In multi-user (mu) security, a total number of BC invocations by all users $\sigma$ and the maximum number of BC invocations per user $\sigma_\mathsf{u}$ are crucial factors. For $\textsf{GCM}$, the tight mu-security bound has been identified as $\frac{\sigma_\mathsf{u} \sigma}{2^n} + \frac{u p + u^2}{2^k}$, where $k$ and $n$ are respectively the key and block sizes, $u$ is the number of users, $p$ is the number of offline queries.In contrast, the $\mathsf{CCM}$'s mu-security bound is still unclear. Two bounds of $\frac{u \sigma_\mathsf{u}^2}{2^n} + \frac{u p + u^2}{2^k}$ and $\frac{\sigma^2}{2^n} + \frac{u p + u \sigma}{2^k}$ have been derived by Luykx~et~al.~(Asiacrypt~2017) and Zhang~et~al.~(CCS~2024), respectively, but both are not tight and worse than the $\textsf{GCM}$'s bound. Moreover, methods to enhance mu security without disruptive changes in the scheme have been considered for $\textsf{GCM}$, namely nonce randomization ($\textsf{NR}$) to improve offline security and nonce-based key derivation ($\textsf{KD}$) to improve online security, but their applicability to $\textsf{CCM}$ has never been discussed. In this paper, we prove an improved mu-security bound of $\textsf{CCM}$, which is tight, and reaches the $\textsf{GCM}$'s bound. We then prove that $\textsf{NR}$ and $\textsf{KD}$ applied to $\textsf{CCM}$ result in the same bounds for the case to $\textsf{GCM}$. An important takeaway is that $\textsf{CCM}$ is now proved to be as secure as $\textsf{GCM}$. Moreover, we argue that $\textsf{NR}$ and $\textsf{KD}$ can be insufficient for some applications with massive data, and propose a new enhancement method called nonce-based and tag-based key derivation ($\textsf{NTKD}$) that is applied to $\textsf{GCM}$ and $\textsf{CCM}$. We prove that the resulting schemes meet such real-world needs.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
CCMGCMMulti-User SecuritySecurity ProofNonce RandomizationNonce-Based and Tag-Based Key Derivation
Contact author(s)
Naito Yusuke @ ce mitsubishielectric co jp
yusk sasaki @ ntt com
sugawara @ uec ac jp
History
2025-05-29: revised
2025-05-26: received
See all versions
Short URL
https://ia.cr/2025/953
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/953,
      author = {Yusuke Naito and Yu Sasaki and Takeshi Sugawara},
      title = {Tight Multi-User Security of {CCM} and Enhancement by Tag-Based Key Derivation Applied to {GCM} and {CCM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/953},
      year = {2025},
      url = {https://eprint.iacr.org/2025/953}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.