Javascript must be enabled to continue!
Security of the Suffix Keyed Sponge
View through CrossRef
We formalize and analyze the general suffix keyed sponge construction, a pseudorandom function built on top of a cryptographic permutation. The construction hashes its data using the (keyless) sponge construction, transforms part of the state using the secret key, and generates the tag from the output of a final permutation call. In its simplest form, if the key and tag size are at most the rate of the sponge, one can see the suffix keyed sponge as a simple sponge function evaluation whose input is the plaintext appended with the key. The suffix keyed sponge is, however, much more general: the key and tag size may exceed the rate without any need to make extra permutation calls. We prove that the suffix keyed sponge construction achieves birthday-bound PRF security in the capacity, even if key and tag size exceed the rate. Furthermore, we prove that if the absorption of the key into the state happens in a leakage resilient manner, the suffix keyed sponge itself is leakage resilient as well. Our findings show that the suffix keyed sponge compares favorably with the hash-then-MAC construction. For instance, to reach a security level of k bits, the side-channel protected component in the suffix keyed sponge just needs to process k bits of input besides the key, whereas schemes following the hash-then-MAC construction need a side-channel protected MAC function that processes 2k bits of input besides the key. Moreover, even if we just consider black-box attacks, the MAC function in a hash-then-MAC scheme needs to be cryptographically strong whereas in the suffix keyed sponge the key may be absorbed by a simple XOR. The security proofs are performed using the H-coefficient technique, and make effective use of the multicollision limit function results of Daemen et al. (ASIACRYPT 2017), both for arguing that state manipulation larger than the rate is tolerated after key processing and for upper bounding the amount of leakage an attacker may gain about the secret key.
Universitatsbibliothek der Ruhr-Universitat Bochum
Title: Security of the Suffix Keyed Sponge
Description:
We formalize and analyze the general suffix keyed sponge construction, a pseudorandom function built on top of a cryptographic permutation.
The construction hashes its data using the (keyless) sponge construction, transforms part of the state using the secret key, and generates the tag from the output of a final permutation call.
In its simplest form, if the key and tag size are at most the rate of the sponge, one can see the suffix keyed sponge as a simple sponge function evaluation whose input is the plaintext appended with the key.
The suffix keyed sponge is, however, much more general: the key and tag size may exceed the rate without any need to make extra permutation calls.
We prove that the suffix keyed sponge construction achieves birthday-bound PRF security in the capacity, even if key and tag size exceed the rate.
Furthermore, we prove that if the absorption of the key into the state happens in a leakage resilient manner, the suffix keyed sponge itself is leakage resilient as well.
Our findings show that the suffix keyed sponge compares favorably with the hash-then-MAC construction.
For instance, to reach a security level of k bits, the side-channel protected component in the suffix keyed sponge just needs to process k bits of input besides the key, whereas schemes following the hash-then-MAC construction need a side-channel protected MAC function that processes 2k bits of input besides the key.
Moreover, even if we just consider black-box attacks, the MAC function in a hash-then-MAC scheme needs to be cryptographically strong whereas in the suffix keyed sponge the key may be absorbed by a simple XOR.
The security proofs are performed using the H-coefficient technique, and make effective use of the multicollision limit function results of Daemen et al.
(ASIACRYPT 2017), both for arguing that state manipulation larger than the rate is tolerated after key processing and for upper bounding the amount of leakage an attacker may gain about the secret key.
Related Results
Modelling regime shifts of coral reefs to sponge reefs
Modelling regime shifts of coral reefs to sponge reefs
<p>Coral reef ecosystems have been degrading globally for decades due to global climate change and anthropogenic pressure, and corals are expected to continue declining in th...
ADJECTIVE SUFFIXES IN THE HATE U GIVE NOVEL: ITS FORMS AND QUANTITIES
ADJECTIVE SUFFIXES IN THE HATE U GIVE NOVEL: ITS FORMS AND QUANTITIES
: This study aims to classify and describe the types of suffixes used to form adjectives found in novel titled The Hate U Give, determine the meanings indicated by the process as ...
Analysis Of The Sensory Quality Of Rolled Cake Using Coconut Milk Fat
Analysis Of The Sensory Quality Of Rolled Cake Using Coconut Milk Fat
This research was motivated by the high trans fat content in margarine which is associated with an increased risk of heart disease and there has been no research on the effect of u...
Suffix Tree Data Structures for Matrices
Suffix Tree Data Structures for Matrices
We discuss the suffix tree generalization to matrices in this chapter. We extend the suffix tree notion (described in Chapter 3) from text strings to text matrices whose entries ar...
Boring Sponges and Bored Oysters – Interactions
between the Bioeroding Sponge Cliona sp. and the New Zealand Flat Oyster Ostrea chilensis
Boring Sponges and Bored Oysters – Interactions
between the Bioeroding Sponge Cliona sp. and the New Zealand Flat Oyster Ostrea chilensis
<p><strong>Bioeroding sponges are the dominant macroborers in many environments. They can affect growth, condition and potentially survival in shellfish populations and...
Effects of marine heatwaves on temperate sponge physiology and reproduction
Effects of marine heatwaves on temperate sponge physiology and reproduction
<p><b>Climate change is causing not only a gradual rise in global temperatures but also an increase in the frequency and severity of climate extremes. Marine Heat Waves...
Trophic interactions of marine sponges
Trophic interactions of marine sponges
<p>Marine communities in the Anthropocene are changing rapidly with potentially severe consequences for ecosystem functioning. Recently, there has been increased interest in ...
Deck-Based Wide Block Cipher Modes and an Exposition of the Blinded Keyed Hashing Model
Deck-Based Wide Block Cipher Modes and an Exposition of the Blinded Keyed Hashing Model
We present two tweakable wide block cipher modes from doubly-extendable cryptographic keyed (deck) functions and a keyed hash function: double-decker and docked-double-decker. Doub...

