Tight security analysis of the public permutation-based PMAC\_Plus
Pseudo-random functions (PRF) are one of the fundamental building blocks of modern cryptography. Therefore, it is paramount to have secure and efficient constructions.\N\NSome of the most commonly used block cipher-based PRFs offer a security bound of up to \(2^{n/2}\) adversarial queries, where \(n\) is the block size. These constructions are said to provide birthday-bound security. In practice, instantiating birthday bounds secure PRF constructions with block ciphers that have a moderate block size can offer enough security. For example, in the case of instantiating the PMAC construction with AES-128, we obtain that \(2^{48}\) adversarial queries are needed for breaking the scheme with a success probability of \(2^{-10}\), assuming that the longest message is \(2^{16}\). Note that, in constrained environments, message sizes are often less than \(1 \text{MB} = 2^{23}\) bits.\N\NHowever, the growing trend of designing lightweight ciphers suitable for constrained environments (e.g. Internet of Things devices) leads to the need to construct PRFs that provide beyond-birthday-bound security. For instance, if we take the same PMAC construction and instantiate it with PRESENT (a lightweight block cipher), the security is reduced to only \(2^{16}\) adversarial queries. Therefore, it is not secure to instantiate birthday-bound secure PRFs with lightweight block ciphers. In this context, several such constructions have emerged.\N\NThe authors of this paper give an extensive overview of them. They also argue that block cipher-based designs are over-engineered and that simpler alternatives are available namely permutation-based constructions. A comparison between permutation-based PRFs and MACs is provided in terms of the number of permutations/keys, and the overall security margin.\N\NIn this context, the authors remark that previous beyond-the-birthday-bound secure PRF proposals based on permutations rely on an almost-xor-universal hash function. As a result, implementing such designs requires more resources than a design based solely on a permutation. This is exactly the solution proposed by the authors: a design based solely on a public permutation that achieves beyond birthday-bound security. Therefore, making it suitable for lightweight cipher instantiations. Additionally, their proposal is constructed such that it is parallel.\N\NAlthough the proposed solution is simple, the authors take great care to rigorously prove the security of the scheme, devoting 23 out of 35 pages to the security proof and complementary key-recovery attack. It is important to note that the provided security bound is tight.
- How to build pseudorandom functions from public random permutations
- A new variant of PMAC: beyond the birthday bound
- Beyond-birthday secure domain-preserving PRFs from a single permutation
- Categorization of faulty nonce misuse resistant message authentication
- \(\mathsf{CENCPP}^\ast\): beyond-birthday-secure encryption from public permutations
- 3kf9: enhancing 3GPP-MAC beyond the birthday bound
- \(\mathsf{CENCPP}^\ast\): beyond-birthday-secure encryption from public permutations
- \textsc{Ascon} v1.2: lightweight authenticated encryption and hashing
- A new variant of PMAC: beyond the birthday bound
- BBB secure nonce based MAC using public permutations
- Blockcipher-based MACs: beyond the birthday bound without message length
- Chaskey: an efficient MAC algorithm for 32-bit microcontrollers
- EWCDM: An Efficient, Beyond-Birthday Secure, Nonce-Misuse Resistant MAC
- Generic attacks against beyond-birthday-bound MACs
- GIFT: a small present. Towards reaching the limit of lightweight encryption
- How to build pseudorandom functions from public random permutations
- scientific article; zbMATH DE number 1962141 (Why is no real title available?)
- scientific article; zbMATH DE number 2086719 (Why is no real title available?)
- Improved security analysis of PMAC
- Mind the composition: birthday bound attacks on EWCDMD and SoKAC21
- Minimizing the two-round Even-Mansour cipher
- Multi-user BBB security of public permutations based MAC
- PRESENT: An Ultra-Lightweight Block Cipher
- SPONGENT: The Design Space of Lightweight Cryptographic Hashing
- The PHOTON family of lightweight hash functions
- The security of the cipher block chaining message authentication code
- The sum of CBC MACs is a secure PRF
- The “Coefficients H” Technique
- Tight security bounds for double-block hash-then-sum MACs
- Tight security bounds for key-alternating ciphers
- Tweaking Even-Mansour ciphers
This page was built for publication: Tight security analysis of the public permutation-based \(\mathsf{PMAC\_Plus} \)
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q6605894)