4 ms·
Internally, is AEAD just using the "usual" ciphers, digests, and PRNGs, just making sure to combine them in the right way? If so, are all AEAD "ciphers" the sam
by twic 1y ago
Internally, is AEAD just using the "usual" ciphers, digests, and PRNGs, just making sure to combine them in the right way? If so, are all AEAD "ciphers" the same, just with different sub-primitives plugged in?
- tptacek 1y agoNot generally. An AEAD composed the way you're describing, out of (say) non-authenticated CTR mode and an HMAC MAC, would be described as "a generic composition". The more common AEADs, at least the way we think about them, aren't compositions of otherwise user-serviceable components. I'm not sure there's a name for them; they're the norm, so we describe those integrated, hermetically-sealed constructions (like GCM) as "AEAD".
- coppsilgold 1y agoAn AEAD can be constructed from pieces made and studied for other purposes (eg. block ciphers and hash functions). There is also a cryptographic primitive which can be used for AEAD almost without modification: the cryptographic sponge. But even so this particular primitive is often tailored for the security requirements of AEAD to be more performant: https://ascon.isec.tugraz.at/specification.html https://ascon.isec.tugraz.at/specification.html An AEAD can also be made de novo. Such as AEGIS[1], which performs encryption and authentication in one pass (much like the sponges, but much more performant). [1] <https://competitions.cr.yp.to/round3/aegisv11.pdf https://competitions.cr.yp.to/round3/aegisv11.pdf>
- syncsynchalt 1y agoEven if you combine the operations so that it works, it may not be obvious whether you've opened yourself to side channels like timing attacks. A naive implementation of the AEAD feature list could trivially allow you to guess the AD for a ciphertext if the AD validation is checked too early in the process.