# American Institute of Mathematical Sciences

November  2019, 13(4): 705-732. doi: 10.3934/amc.2019042

## $\textsf{DWCDM+}$: A BBB secure nonce based MAC

 1 Indian Statistical Institute, Kolkata, India 2 NTT Secure Platform Laboratories, NTT Corporation, Japan

* Corresponding author

Received  November 2018 Revised  January 2019 Published  June 2019

Fund Project: This is an extended version of the article accepted in IACR-CRYPTO 2018. Section 3, section 4 and section 5 contains the substantial changes from our article accepted in IACR-CRYPTO 2018. Mridul Nandi is supported by R.C.Bose Centre for Cryptology and Security

In CRYPTO 2016, Cogliati and Seurin have proposed a nonce-based MAC called Encrypted Wegman-Carter with Davies-Meyer (
 $\textsf{EWCDM}$
), from an
 $n$
-bit block cipher
 $\textsf{E}$
and an
 $n$
-bit almost xor universal hash function
 $\textsf{H}$
as
 $\textsf{E}_{K_2}\bigl(\textsf{E}_{K_1}(N)\oplus N\oplus \textsf{H}_{K_h}(M)\bigr),$
for a nonce
 $N$
and a message
 $M$
that provides roughly
 $2n/3$
-bit MAC security. However, obtaining the similar security using a single block cipher key was posed as an open research problem. In this paper, we present Decrypted Wegman-Carter with Davies-Meyer (
 $\textsf{DWCDM+}$
) construction based on a single block cipher key that provides
 $2n/3$
-bit MAC security from an
 $n$
-bit block cipher
 $\textsf{E}$
and an
 $n$
-bit
 $k$
-regular (
 $\forall k \leq n$
), almost xor universal hash function
 $\textsf{H}$
as
 $\textsf{E}^{-1}_{K}\bigl(\textsf{E}_{K}(N)\oplus N \oplus \textsf{H}_{K_h}(M)\bigr).$
 $\textsf{DWCDM+}$
is structurally very similar to its predecessor
 $\textsf{EWCDM}$
except that the facts that (i) the number of block cipher keys reduced from
 $2$
to
 $1$
and (ⅱ) the outer encryption call is replaced by a decryption one. To make the construction truely single-keyed, here we derive the hash key
 $K_h$
as the block cipher output of a fixed string
 $0^{n-2} \| 10$
as long as the hash key is of
 $n$
bits. We show that if the nonce space is restricted to
 $(n-1)$
bits,
 $\textsf{DWCDM+}$
is secured roughly up to
 $2^{2n/3}$
MAC queries (
 $2^{n/2}$
MAC queries) and
 $2^n$
verification queries against nonce respecting (nonce misuse resp.) adversaries.
Citation: Nilanjan Datta, Avijit Dutta, Mridul Nandi, Kan Yasuda. $\textsf{DWCDM+}$: A BBB secure nonce based MAC. Advances in Mathematics of Communications, 2019, 13 (4) : 705-732. doi: 10.3934/amc.2019042
##### References:

show all references

##### References:
$\textsf{DWCDM+}$ construction with an n-bit block cipher EK and n-bit keyed hash function HL where L = EK(0n−2║10).
Birthday bound MAC attack against $\textsf{DWCDM+}$ if full nonce space is used.
 [1] Harbir Antil, Mahamadi Warma. Optimal control of the coefficient for the regional fractional $p$-Laplace equation: Approximation and convergence. Mathematical Control & Related Fields, 2019, 9 (1) : 1-38. doi: 10.3934/mcrf.2019001 [2] Florin Diacu, Shuqiang Zhu. Almost all 3-body relative equilibria on $\mathbb S^2$ and $\mathbb H^2$ are inclined. Discrete & Continuous Dynamical Systems - S, 2018, 0 (0) : 1-13. doi: 10.3934/dcdss.2020067 [3] Ildoo Kim. An $L_p$-Lipschitz theory for parabolic equations with time measurable pseudo-differential operators. Communications on Pure & Applied Analysis, 2018, 17 (6) : 2751-2771. doi: 10.3934/cpaa.2018130 [4] Sugata Gangopadhyay, Goutam Paul, Nishant Sinha, Pantelimon Stǎnicǎ. Generalized nonlinearity of $S$-boxes. Advances in Mathematics of Communications, 2018, 12 (1) : 115-122. doi: 10.3934/amc.2018007 [5] Gyula Csató. On the isoperimetric problem with perimeter density $r^p$. Communications on Pure & Applied Analysis, 2018, 17 (6) : 2729-2749. doi: 10.3934/cpaa.2018129 [6] Haisheng Tan, Liuyan Liu, Hongyu Liang. Total $\{k\}$-domination in special graphs. Mathematical Foundations of Computing, 2018, 1 (3) : 255-263. doi: 10.3934/mfc.2018011 [7] Pak Tung Ho. Prescribing the $Q'$-curvature in three dimension. Discrete & Continuous Dynamical Systems - A, 2019, 39 (4) : 2285-2294. doi: 10.3934/dcds.2019096 [8] Ekta Mittal, Sunil Joshi. Note on a $k$-generalised fractional derivative. Discrete & Continuous Dynamical Systems - S, 2018, 0 (0) : 797-804. doi: 10.3934/dcdss.2020045 [9] Eun-Kyung Cho, Cunsheng Ding, Jong Yoon Hyun. A spectral characterisation of $t$-designs and its applications. Advances in Mathematics of Communications, 2019, 13 (3) : 477-503. doi: 10.3934/amc.2019030 [10] Gang Wang, Yuan Zhang. $Z$-eigenvalue exclusion theorems for tensors. Journal of Industrial & Management Optimization, 2017, 13 (5) : 1-12. doi: 10.3934/jimo.2019039 [11] Caili Sang, Zhen Chen. $E$-eigenvalue localization sets for tensors. Journal of Industrial & Management Optimization, 2017, 13 (5) : 1-19. doi: 10.3934/jimo.2019042 [12] Annalisa Cesaroni, Serena Dipierro, Matteo Novaga, Enrico Valdinoci. Minimizers of the $p$-oscillation functional. Discrete & Continuous Dynamical Systems - A, 2019, 0 (0) : 1-15. doi: 10.3934/dcds.2019231 [13] Zalman Balanov, Yakov Krasnov. On good deformations of $A_m$-singularities. Discrete & Continuous Dynamical Systems - S, 2019, 12 (7) : 1851-1866. doi: 10.3934/dcdss.2019122 [14] Lin Du, Yun Zhang. $\mathcal{H}_∞$ filtering for switched nonlinear systems: A state projection method. Journal of Industrial & Management Optimization, 2018, 14 (1) : 19-33. doi: 10.3934/jimo.2017035 [15] Shengbing Deng. Construction solutions for Neumann problem with Hénon term in $\mathbb{R}^2$. Discrete & Continuous Dynamical Systems - A, 2019, 39 (4) : 2233-2253. doi: 10.3934/dcds.2019094 [16] Teresa Alberico, Costantino Capozzoli, Luigi D'Onofrio, Roberta Schiattarella. $G$-convergence for non-divergence elliptic operators with VMO coefficients in $\mathbb R^3$. Discrete & Continuous Dynamical Systems - S, 2019, 12 (2) : 129-137. doi: 10.3934/dcdss.2019009 [17] Mohan Mallick, R. Shivaji, Byungjae Son, S. Sundar. Bifurcation and multiplicity results for a class of $n\times n$ $p$-Laplacian system. Communications on Pure & Applied Analysis, 2018, 17 (3) : 1295-1304. doi: 10.3934/cpaa.2018062 [18] Daniel Heinlein, Michael Kiermaier, Sascha Kurz, Alfred Wassermann. A subspace code of size $\bf{333}$ in the setting of a binary $\bf{q}$-analog of the Fano plane. Advances in Mathematics of Communications, 2019, 13 (3) : 457-475. doi: 10.3934/amc.2019029 [19] Guoyuan Chen, Yong Liu, Juncheng Wei. Nondegeneracy of harmonic maps from ${{\mathbb{R}}^{2}}$ to ${{\mathbb{S}}^{2}}$. Discrete & Continuous Dynamical Systems - A, 2019, 0 (0) : 1-19. doi: 10.3934/dcds.2019228 [20] Joackim Bernier. Bounds on the growth of high discrete Sobolev norms for the cubic discrete nonlinear Schrödinger equations on $h\mathbb{Z}$. Discrete & Continuous Dynamical Systems - A, 2019, 39 (6) : 3179-3195. doi: 10.3934/dcds.2019131