On the Security of Encrypt-and-MAC Paradigm

Hu Zhenyu,Lin Dongdai,Wu Wenling,Feng Dengguo
IF: 1.019
2007-01-01
Chinese Journal of Electronics
Abstract:A security notion of Message authentication (MAC) named Tag-secrecy was abstracted from the pseudo-randomness of tagging algorithm, to characterize the security that is very different from the unforgeability (which is the traditional security notion of MAC). The Tag-secrecy is weaker than the pseudo-randomness and can be met by widely used authentication schemes. Under the assumption of Tag-secrecy, it is showed that the Encryptand-MAC can preserve Indistinguishability under Chosen-plaintext attacks (IND-CPA) and Integrity of Plaintext (INT-PTXT) in general.A security notion of encryption called Un-trivial forgeability of Ciphertext (UTF-CTXT) was presented to characterize that for any given ciphertext C, the adversary cannot forge a new ciphertext C' to decrypt to the same plaintext as C (named trivial forgery). This UTF-CTXT was to guarantee that any modification about the ciphertext must correspond to some change of the plaintext. It is proved to be much weaker than Integrity of Ciphertext (INT-CTXT) and satisfied by many popular encryption schemes and modes.With a Tag-secrecy MAC and an UTF-CTXT-secure encryption, Encrypt-and-MAC can satisfy the both strongest security requirements-Indistinguishability under Chosen-ciphertext attacks (IND-CCA) and INT-CTXT.
What problem does this paper attempt to address?