Abstract:
We describe an attack on the “$8$ bits” authentication encryption with associated data ($\mathsf{AEAD}$) mode proposed during the $\mathsf{AEAD}$ standardization process. The “$8$ bits” mode is similar to the $\mathrm{CCM}$ mode except for several design features. We show that these distinctive features allow to construct a near birthday attack on “$8$ bits” mode. We also propose countermeasures to resist suggested attack.