By Thomas Peyrin

This publication constitutes the completely refereed post-conference complaints of the twenty third overseas convention on quick software program Encryption, held in Bochum, Germany, in March 2016. The 29 revised complete papers awarded have been rigorously reviewed and chosen from 86 preliminary submissions. The papers are prepared in topical sections on working modes; stream-cipher cryptanalysis; elements; side-channels and implementations; computerized instruments for cryptanalysis; designs; block-cipher cryptanalysis; foundations and idea; and authenticated-encryption and hash functionality cryptanalysis.

Example text

HCTR: a variable-input-length enciphering mode. , Yung, M. ) CISC 2005. LNCS, vol. 3822, pp. 175–188. Springer, Heidelberg (2005) 51. : A new algorithm for inner product. IEEE Trans. Comput. jp Abstract. Lightweight cryptography strives to protect communication in constrained environments without sacrificing security. However, security often conflicts with efficiency, shown by the fact that many new lightweight block cipher designs have block sizes as low as 64 or 32 bits. Such low block sizes lead to impractical limits on how much data a mode of operation can process per key.

A nonce-based authenticated encryption scheme (with associated data) [44] is a tuple Π = (E, D) of a deterministic encryption algorithm E : K×N ×H×M → C ×T , and a deterministic decryption algorithm D : K×N ×H×C ×T → M∪{⊥}, with associated non-empty key space K, nonempty nonce space N , and H, M, C ⊆ {0, 1}∗ denote the header, message, and ciphertext space, respectively. We define a tag space T = {0, 1}τ for a fixed τ ≥ 0. N,H N,H We often write EK (M ) and DK (C, T ) as short forms of E(K, N, H, M ) and N,H D(K, N, H, C, T ).

Then, we define the SRND (A) := ΔA (EK , DK ; $E , $D ). 2 Security Definitions for Nonce-Based AE Schemes For this subsection, let Π = (E, D) be a nonce-based AE scheme, K A be a computationally bounded adversary on Π. K, and Definition 8 (IND-CPA Advantage). Let A have access to an encryption oracle. Then, the IND-CPA advantage of A with respect to Π is defined as AdvIND-CPA (A) := ΔA (EK ; $E ). Π Definition 9 (INT-CTXT Advantage). Let A have access to two oracles O1 and O2 such that A never queries O1 → O2 .

