Paper 2026/439

The OCH Authenticated Encryption Scheme

Sanketh Menda, Cornell Tech
Mihir Bellare, University of California, San Diego
Viet Tung Hoang, Florida State University
Julia Len, UNC Chapel Hill
Thomas Ristenpart, University of Toronto
Abstract

We specify OCH, the first authenticated encryption with associated data scheme built to provide 128-bit multi-user AE security, 128-bit context commitment security, and 256-bit nonces with optional nonce privacy. It therefore addresses pressing limitations of currently widely-deployed schemes. We construct and formally analyze the security of OCH in a modular fashion, with transforms that are of broader applicability. On Intel Raptor Lake CPUs, OCH using the Areion permutation family has a peak encryption speed of 0.62 cycles per byte (cpb), not far off from AES128-GCM (0.38cpb) and outperforming both ChaCha20/Poly1305 (1.63cpb) and TurboSHAKE128-Wrap (3.52cpb).

Note: Update includes some minor corrections to typos, including a constant in Theorem 3.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published elsewhere. Minor revision. ACM CCS 2025
Contact author(s)
sm2289 @ cornell edu
mihir @ eng ucsd edu
tvhoang @ cs fsu edu
jlen @ cs unc edu
ristenpart @ cs toronto edu
History
2026-03-16: revised
2026-03-04: received
See all versions
Short URL
https://ia.cr/2026/439
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/439,
      author = {Sanketh Menda and Mihir Bellare and Viet Tung Hoang and Julia Len and Thomas Ristenpart},
      title = {The {OCH} Authenticated Encryption Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/439},
      year = {2026},
      url = {https://eprint.iacr.org/2026/439}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.