Paper 2025/758
Blockcipher-Based Key Commitment for Nonce-Derived Schemes
Abstract
AES-GCM has seen great adoption for the last 20 years to protect data in various use-cases because of its optimal performance. It has also posed some challenges to modern applications due to its nonce, block size, and lack of key commitment. Nonce-derived schemes address these challenges by deriving a different key from random values and using GCM with the derived key. In this work, we explore efficient key commitment methods for nonce-derived schemes. For concreteness, we focus on expanding XAES-256-GCM, a derived key scheme originally introduced by Filippo Valsorda. We propose an efficient CMAC-based key commitment solution, and prove its security in the ideal-cipher model. This proposal yields a FIPS-compliant mode and offers much better data bounds than GCM. Finally, we benchmark the new mode's performance to demonstrate that the additional cost affects mostly small plaintexts.
Metadata
- Available format(s)
-
PDF
- Category
- Foundations
- Publication info
- Published elsewhere. SAC 2025
- Keywords
- XAESKC-XAESKey Committing AEADCMAC based key commitment
- Contact author(s)
-
kpanos @ amazon com
shaihal @ amazon com
nebeid @ amazon com
campagna @ amazon com - History
- 2025-09-02: last of 3 revisions
- 2025-04-28: received
- See all versions
- Short URL
- https://ia.cr/2025/758
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/758,
author = {Panos Kampanakis and Shai Halevi and Nevine Ebeid and Matt Campagna},
title = {Blockcipher-Based Key Commitment for Nonce-Derived Schemes},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/758},
year = {2025},
url = {https://eprint.iacr.org/2025/758}
}