Optimally Secure Tweakable Block Ciphers with a Large Tweak from n-bit Block Ciphers

(2023) {IACR} Trans. Symmetric Cryptol. — Vol. 2023, n° 2, p. 47-68 (2023)

Files

ToSC2023_2_02.pdf
  • Open Access
  • Adobe PDF
  • 823.31 KB

Details

Authors
Abstract
We consider the design of a tweakable block cipher from a block cipherwhose inputs and outputs are of sizenbits. The main goal is to achieve2nsecuritywith a large tweak (i.e., more thannbits). Previously, Mennink at FSE’15 and Wanget al. at Asiacrypt’16 proposed constructions that can achieve2nsecurity. Yet, theseconstructions can have a tweak size up ton-bit only. As evident from recent research,a tweakable block cipher with a large tweak is generally helpful as a building block formodes of operation, typical applications including MACs, authenticated encryption,leakage-resistant cryptography and full-disk encryption.We begin with how to design a tweakable block cipher with2n-bit tweak andn-bitsecurity from two block cipher calls. For this purpose, we do an exhaustive search fortweakable block ciphers with2n-bit tweaks from two block cipher calls, and show thatall of them suffer from birthday-bound attacks. Next, we investigate the possibilityto design a tweakable block cipher with2n-bit tweak andn-bit security from threeblock cipher calls. We start with some conditions to build such a tweakable blockcipher and propose a natural construction, called ̃G1, that likely meets them. Afterinspection, we find a weakness in ̃G1which leads to a birthday-bound attack. Basedon ̃G1, we then propose another construction, called ̃G2, that can avoid this weakness.We finally prove that ̃G2can achieven-bit security with2n-bit tweak.
Affiliations

Citations

Shen, Y., & Standaert, F.-X. (2023). Optimally Secure Tweakable Block Ciphers with a Large Tweak from n-bit Block Ciphers. {IACR} Trans. Symmetric Cryptol., 2023(2), 47-68. https://doi.org/10.46586/tosc.v2023.i2.47-68 (Original work published 2023)