3 ms·
Encrypt-Then-Mac for Committing AEAD (CAEAD) Internet Draft
- samuel-lucas6 4y agoThis draft aims to address three problems: 1. It explains how to construct an AEAD scheme by combining an unauthenticated cipher and collision-resistant, hash-based MAC. To my knowledge, this has not been written up before. It's important because it's more flexible than regular Encrypt-then-MAC without associated data and provides a standardised approach for implementation. 2. AEAD schemes like AES-GCM, ChaCha20-Poly1305, and AES-OCB aren't committing. A committing scheme is required in some scenarios (e.g. password-based encryption) and should really be the default to prevent attacks. 3. There still seems to be a lack of awareness that AEADs are not committing. This attempts to summarise what it means since the topic is confusing. Any feedback would be much appreciated.