TY - JOUR AU - Minematsu, Kazuhiko PY - 2020/09/28 Y2 - 2024/03/28 TI - Fast Decryption: a New Feature of Misuse-Resistant AE JF - IACR Transactions on Symmetric Cryptology JA - ToSC VL - 2020 IS - 3 SE - Articles DO - 10.13154/tosc.v2020.i3.87-118 UR - https://tosc.iacr.org/index.php/ToSC/article/view/8697 SP - 87-118 AB - <p>Misuse-resistant AE (MRAE) is a class of authenticated encryption (AE) that has a resistance against a potential misuse (repeat) of nonce. MRAE has received significant attention from the initial proposal by Rogaway and Shrimpton. They showed a generic MRAE construction called SIV. SIV becomes a de-facto scheme for MRAE, however, one notable drawback is its two-pass operation for both encryption and decryption. This implies that MRAE built on SIV is slower than the integrated nonce-based AE schemes, such as OCB.<br>In this paper, we propose a new method to improve this situation. Particularly, our MRAE proposal (decryption-fast SIV or DFV) allows to decrypt as fast as a plain decryption, hence theoretically doubles its speed from the original SIV, while keeping the encryption speed equivalent to SIV. We present several generic compositions for DFV and their instantiations.</p> ER -