Activités par an
Résumé
OCB3 is a mature and provably secure authenticated encryption mode of operation which allows for associated data (AEAD). This note reports a small flaw in the security proof of OCB3 that may cause a loss of security in practice, even if OCB3 is correctly implemented in a trustworthy and nonce-respecting module. The flaw is present when OCB3 is used with short nonces. It has security implications that are worse than nonce-repetition as confidentiality and authenticity are lost until the key is changed. The flaw is due to an implicit condition in the security proof and to the way OCB3 processes nonces. Different ways to fix the mode are presented.
| langue originale | Anglais |
|---|---|
| Numéro d'article | 106404 |
| journal | Information Processing Letters |
| Volume | 183 |
| Les DOIs | |
| état | Publié - janv. 2024 |
Empreinte digitale
Examiner les sujets de recherche de « A weakness in OCB3 used with short nonces allowing for a break of authenticity and confidentiality ». Ensemble, ils forment une empreinte digitale unique.Activités
- 1 Présentation orale à caractère scientifique
-
OCB 1, 2, 3: the good, the bad and the ugly (EuroCrypt 2023 rump session)
Liénardy, J. (Orateur plénier)
25 avr. 2023Activité: Conférence ou présentation › Présentation orale à caractère scientifique