Paper 2026/1981

Parallelized Authenticated Encryption with Tag Combiners

Christoph Dobraunig, Intel (United States)
Charlotte Lefevre, Univ Rennes, Inria, CNRS, IRISA
Abstract

When looking at authenticated encryption schemes, we have schemes that process the input data by having serial calls to their underlying building blocks, like duplex-based constructions, and schemes that allow for parallel calls to their underlying building blocks, like the Galois Counter Mode (GCM). Naturally, one can parallelize a serial scheme by distributing the data to encrypt over different calls to the serial scheme. However, there are many different choices to be made, like how to choose the nonce for the different instances, or if and how to combine the multiple tags into a single one. In this paper, we investigate different possible choices providing proofs for their security. Interestingly, we see a huge variance in the provable properties and hence, the security in making a serial scheme parallel. Or, motivating the problem more generally, we are investigating tag combiners, where the single tags to be combined are secret to the adversary.

Note: Full version of the ISC version

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published elsewhere. Major revision. ISC
Keywords
authenticated encryptionparallelizationprovable security
Contact author(s)
christoph dobraunig @ intel com
charlotte lefevre @ irisa fr
History
2026-09-13: approved
2026-09-11: received
See all versions
Short URL
https://ia.cr/2026/1981
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1981,
      author = {Christoph Dobraunig and Charlotte Lefevre},
      title = {Parallelized Authenticated Encryption with Tag Combiners},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1981},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1981}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.