International audienceWe study Authenticated Encryption with Associated Data (AEAD) from the viewpoint of composition in arbitrary (single-stage) environments. We use the indifferentiability framework to formalize the intuition that a "good" AEAD scheme should have random ciphertexts subject to de-cryptability. Within this framework, we can then apply the indifferentiability composition theorem to show that such schemes offer extra safeguards wherever the relevant security properties are not known, or cannot be predicted in advance, as in general-purpose crypto libraries and standards. We show, on the negative side, that generic composition (in many of its configurations) and well-known classical and recent schemes fail to achieve indiffere...
A major general paradigm in cryptography is the following argument: Whatever an adversary could do i...
We provide a new definitional framework capturing the multi-user security of encryption schemes and ...
The algebraic-group model (AGM), which lies between the generic group model and the standard model o...
We study Authenticated Encryption with Associated Data (AEAD) from the viewpoint of composition in a...
We prove that a balanced 8-round Feistel network is indifferentiable from a random permutation. This...
In this thesis we consider different problems related to provable security and indifferentiability f...
Iterated Even-Mansour scheme (IEM) is a generalization of the basic 1-round proposal (ASIACRYPT \u27...
An authenticated encryption scheme is deemed secure (AE) if ciphertexts both look like random bitstr...
The Advanced Encryption Standard (AES) is the most widely used block cipher. The high level structur...
We prove that a (balanced) 10-round Feistel network is indifferentiable from a random permutation. I...
Committing security has gained considerable attention in the field of authenticated encryption (AE)....
We revisit the question of constructing an ideal cipher from a random oracle. Coron et al.~(Journal ...
The notion of indifferentiability, which is a stronger version of the classic notion of indistinguis...
Functional encryption enables fine-grained access to encrypted data. In many scenarios, however, it ...
peer reviewedWe describe the first domain extender for ideal ciphers, i.e. we show a construction th...
A major general paradigm in cryptography is the following argument: Whatever an adversary could do i...
We provide a new definitional framework capturing the multi-user security of encryption schemes and ...
The algebraic-group model (AGM), which lies between the generic group model and the standard model o...
We study Authenticated Encryption with Associated Data (AEAD) from the viewpoint of composition in a...
We prove that a balanced 8-round Feistel network is indifferentiable from a random permutation. This...
In this thesis we consider different problems related to provable security and indifferentiability f...
Iterated Even-Mansour scheme (IEM) is a generalization of the basic 1-round proposal (ASIACRYPT \u27...
An authenticated encryption scheme is deemed secure (AE) if ciphertexts both look like random bitstr...
The Advanced Encryption Standard (AES) is the most widely used block cipher. The high level structur...
We prove that a (balanced) 10-round Feistel network is indifferentiable from a random permutation. I...
Committing security has gained considerable attention in the field of authenticated encryption (AE)....
We revisit the question of constructing an ideal cipher from a random oracle. Coron et al.~(Journal ...
The notion of indifferentiability, which is a stronger version of the classic notion of indistinguis...
Functional encryption enables fine-grained access to encrypted data. In many scenarios, however, it ...
peer reviewedWe describe the first domain extender for ideal ciphers, i.e. we show a construction th...
A major general paradigm in cryptography is the following argument: Whatever an adversary could do i...
We provide a new definitional framework capturing the multi-user security of encryption schemes and ...
The algebraic-group model (AGM), which lies between the generic group model and the standard model o...