Overview of Authenticated Encryption Modes of Operation

Elena Ivanova Andreeva and Ammar Alkassar

Saarland University

Traditional block cipher modes of operation, namely CBC, CFB, OFB and CTR, provide encryption with achieving the confidentiality goal without any integrity guarantees. On the other hand, there exist authentication modes that are custom-made to ensure integrity. However, they do not provide a secure encryption.

A conventional way to satisfy both security properties, confidentiality and integrity, is to make two separate passes on the data. One encryption pass for the encrypting of the data block cipher-wise, and a second authentication pass for checking the data integrity.

Recently, new unconventional integrity-aware modes of operation for block ciphers have been proposed. They provide confidentiality and integrity by combining authentication modes with the traditional block ciphers making only a single pass on the data. These modes are called authenticated encryption modes. In our presentation we give an overview on some of these newly proposed authenticated encryption modes, like IACBC, IAPM[JU01], XCBC[GD01] and OCB[RBBK01], their properties and advantages for a future use.

References

GD01
V. Gligor, P. Donescu.
Fast encryption and authentication: XCBC Encryption and XECB Authentication modes.
Proceedings of the Fast Software Encryption Workshop - FSE '01. Springer-Verlag, October 2001.

JU01
C. Jutla.
Encryption Modes with Almost Free Message Integrity.
Advances in Cryptology-EUROCRYPT 2001.

RBBK01
P. Rogaway, M. Bellare, J. Black and T. Krovetz.
OCB: A Block-Cipher Mode of Operation for Efficient Authenticated Encryption
ACM Transactions on Information and System Security (TISSEC), vol. 6, no. 3, pp. 365-403, August 2001.