What a lovely hat

Is it made out of tin foil?

Paper 2025/758

Blockcipher-Based Key Commitment for Nonce-Derived Schemes

Panos Kampanakis, Amazon Web Services
Shai Halevi, Amazon Web Services
Nevine Ebeid, Amazon Web Services
Matt Campagna, Amazon Web Services
Abstract

AES-GCM has seen great adoption for the last 20 years to protect data in various use-cases because of its optimal performance. It has also posed some challenges to modern applications due to its nonce, block size, and lack of key commitment. Nonce-derived schemes address these challenges by deriving a different key from random values and using GCM with the derived key. In this work, we explore efficient key commitment methods for nonce-derived schemes. For concreteness, we focus on expanding XAES-256-GCM, a derived key scheme originally introduced by Filippo Valsorda. We propose an efficient CMAC-based key commitment solution, and prove its security in the ideal-cipher model. This proposal yields a FIPS-compliant mode and offers much better data bounds than GCM. Finally, we benchmark the new mode's performance to demonstrate that the additional cost affects mostly small plaintexts.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Published elsewhere. SAC 2025
Keywords
XAESKC-XAESKey Committing AEADCMAC based key commitment
Contact author(s)
kpanos @ amazon com
shaihal @ amazon com
nebeid @ amazon com
campagna @ amazon com
History
2025-09-02: last of 3 revisions
2025-04-28: received
See all versions
Short URL
https://ia.cr/2025/758
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/758,
      author = {Panos Kampanakis and Shai Halevi and Nevine Ebeid and Matt Campagna},
      title = {Blockcipher-Based Key Commitment for Nonce-Derived Schemes},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/758},
      year = {2025},
      url = {https://eprint.iacr.org/2025/758}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.