Reconsidering Generic Composition

نویسندگان

  • Chanathip Namprempre
  • Phillip Rogaway
  • Thomas Shrimpton
چکیده

In the context of authenticated encryption (AE), generic composition has referred to the construction of an AE scheme by gluing together a conventional (privacy-only) encryption scheme and a MAC. Since the work of Bellare and Namprempre (2000) and then Krawczyk (2001), the conventional wisdom has become that there are three forms of generic composition, with Encrypt-then-MAC the only one that generically works. However, many caveats to this understanding have surfaced over the years. Here we explore this issue further, showing how this understanding oversimplifies the situation because it ignores the results’ sensitivity to definitional choices. When encryption is formalized differently, making it either IV-based or nonce-based, rather than probabilistic, and when the AE goal is likewise changed to take in a nonce, qualitatively different results emerge. We explore these alternatives versions of the generic-composition story. We also evidence the overreaching understanding of prior genericcomposition results by pointing out that the Encrypt-then-MAC mechanism of ISO 19772 is completely wrong.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Under consideration for publication in Formal Aspects of Computing Generic Composition

This paper presents a technique called generic composition to provide a uniform basis for modal operators, sequential composition, different kinds of parallel compositions and various healthiness conditions appearing in a variety of semantic theories. The weak inverse of generic composition is defined. A completeness theorem shows that any predicate can be written in terms of generic compositio...

متن کامل

Reconsidering Hadith al-Iftiraq

Hadith al-Iftiraqis a famous hadith attributed to Prophet Muhammad (s) in many Shi‘i and Sunni hadith collections, as well as in heresiographical sources. Among many books written by contemporary heresiographers, few have failed to mention this hadith in their writings. Many Shi‘i and Sunni traditionists have collected the traditions that deal with the future of the Muslim ummah under such titl...

متن کامل

Logic for Media - The Computational Media Metaphor

New media as they are established by information and communications technology demand for reconsidering the notion of a medium as a carrier of information and with it the concepts for representation, organization, processing and dissemination of information. We explore a general model for media, the Computational Media Metaphor and utilize Rewriting Logic and Labelled Deductive Systems to model...

متن کامل

Reconsidering the Selection Concept of Genetic Algorithms from a Population Genetics Inspired Point of View

In this paper we propose some generic extensions to the general selection concept of a Genetic Algorithm (GA). These bionically inspired interrelated further developments aim to make the algorithm more open for scalability on the one hand, and to stabilize the performance of weaker crossover operators on the other hand without necessitating the development of new coding standards and operators ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2014  شماره 

صفحات  -

تاریخ انتشار 2014