Authenticated On-Line Encryption

Abstract : In this paper, we investigate the authenticated encryption paradigm, and its security against blockwise adaptive adversaries, mounting chosen ciphertext attacks on on-the-fly cryptographic devices. We remark that most of the existing solutions are insecure in this context, since they provide a decryption oracle for any ciphertext. We then propose a generic construction called Decrypt-Then-Mask, and prove its security in the blockwise adversarial model. The advantage of this proposal is to apply minimal changes to the encryption protocol. In fact, in our solution, only the decryption protocol is modified, while the encryption part is left unchanged. Finally, we propose an instantiation of this scheme, using the encrypted CBC-MAC algorithm, a secure pseudorandom number generator and the Delayed variant of the CBC encryption scheme.
Pierre-Alain Fouque, Antoine Joux, Gwenaëlle Martinet, Frédéric Valette. Authenticated On-Line Encryption. Selected Areas in Cryptography, 10th Annual International Workshop, SAC 2003, 2004, Ottawa, Canada. pp.145-159, ⟨10.1007/978-3-540-24654-1_11⟩. ⟨inria-00563967⟩



