Paper 2026/383

HCTR$^{++}$ : A Beyond Birthday Bound Secure HCTR2 Variant

Gülnihal Öztürk, Middle East Technical University
Onur Koçak, TUBITAK BILGEM
Oğuz Yayla, Middle East Technical University
Abstract

Current industry-standard block cipher modes of operation, such as CBC and GCM, are fundamentally limited by the birthday bound $O(2^{n/2})$, a constraint that has evolved from a theoretical concern into a practical security bottleneck in contemporary high-throughput, high-data-volume environments. To address this, the cryptographic community and NIST are prioritizing Beyond Birthday Bound (BBB) security to extend the operational security margin toward the full block size $O(2^n)$. Achieving BBB security requires a departure from traditional constructions, primarily utilizing three methodologies: XOR of Permutations (XORP), Tweakable Block Ciphers (TBCs), and Fresh Re-keying. While none of these innovative BBB modes have been formally standardized, NIST has initiated the Accordion Mode project, defining a new primitive class: the Tweakable Variable-Input-Length Strong Pseudorandom Permutation (VIL-SPRP). This primitive treats the entire message as a single, indivisible block and expects the submission of BBB-secure variants. To contribute to this standardization effort, we propose a simple BBB-secure variant of the HCTR2 algorithm based on Fresh Re-keying and a $2n$-bit $\varepsilon$-uniform-AXU keyed hash family. Under the stated hash assumptions and the ideal-cipher model, the construction achieves a beyond-birthday-bound security profile for bounded message lengths and sufficiently restricted tweak repetition. We first explain the core BBB methodologies, then discuss the operational mechanism of HCTR2, and finally present our proposed BBB-secure construction.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Accordion modeBeyond Birthday Bound SecurityHCTR2
Contact author(s)
gulnihal ozturk_01 @ metu edu tr
onur kocak @ tubitak gov tr
oguz @ metu edu tr
History
2026-10-05: last of 4 revisions
2026-02-24: received
See all versions
Short URL
https://ia.cr/2026/383
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2026/383,
      author = {Gülnihal Öztürk and Onur Koçak and Oğuz Yayla},
      title = {{HCTR}$^{++}$ : A Beyond Birthday Bound Secure {HCTR2} Variant},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/383},
      year = {2026},
      url = {https://eprint.iacr.org/2026/383}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.