Find in Library
Search millions of books, articles, and more
Indexed Open Access Databases
Reconsidering the Security Bound of AES-GCM-SIV
oleh: Tetsu Iwata, Yannick Seurin
Format: | Article |
---|---|
Diterbitkan: | Ruhr-Universität Bochum 2017-12-01 |
Deskripsi
We make a number of remarks about the AES-GCM-SIV nonce-misuse resistant authenticated encryption scheme currently considered for standardization by the Crypto Forum Research Group (CFRG). First, we point out that the security analysis proposed in the ePrint report 2017/168 is incorrect, leading to overly optimistic security claims. We correct the bound and re-assess the security guarantees offered by the scheme for various parameters. Second, we suggest a simple modification to the key derivation function which would improve the security of the scheme with virtually no efficiency penalty.