RUS  ENG
Full version
JOURNALS // Matematicheskie Voprosy Kriptografii [Mathematical Aspects of Cryptography] // Archive

Mat. Vopr. Kriptogr., 2023 Volume 14, Issue 3, Pages 49–73 (Mi mvk446)

On the security of authenticated encryption mode with associated data MGM with respect to confidentiality threat

L. R. Akhmetzyanovaa, E. K. Alekseeva, G. A. Karpunina, V. I. Nozdrunovb

a CryptoPro LLC, Moscow
b Technical Committee for Standardization «Cryptography and Security Mechanisms» (TC 26), Moscow

Abstract: The authenticated encryption mode with associated data MGM was first presented at the CTCrypt'2017 conference and subsequently standardized in documents R 1323565.1.026-2019 of the Russian standardization system and RFC 9058 of the IETF organization. The mode is aimed to protect transmitted data in the TLS 1.3 and IPsec protocols with GOST algorithms. In this paper the security of MGM is estimated in a standard security model used for confidentiality analysis, using a complexity-theoretic approach. In other words, lower security bounds of the mode were obtained assuming the security of the block cipher in the PRP-CPA (PseudoRandom Permutations under Chosen Plaintext Attack) model. The obtained bounds show that MGM provides an acceptable security level for a wide range of practically important parameters.

Key words: MGM, AEAD block cipher modes, authenticated encryption, confidentiality, security bounds.

UDC: 519.719.2

Received 06.II.2019

DOI: 10.4213/mvk446



© Steklov Math. Inst. of RAS, 2024