Cornell University
Library
Cornell UniversityLibrary

eCommons

Help
Log In(current)
  1. Home
  2. Cornell University Graduate School
  3. Cornell Theses and Dissertations
  4. Building the Next Generation of Authenticated Encryption

Building the Next Generation of Authenticated Encryption

File(s)
Menda_cornellgrad_0058F_15270.pdf (1.22 MB)
Permanent Link(s)
https://doi.org/10.7298/8fh3-kv52
https://hdl.handle.net/1813/120771
Collections
Cornell Theses and Dissertations
Author
Menda, Sanketh Gora
Abstract

Symmetric encryption is the foundation for secure communication, and its current iteration in widespread use is authenticated encryption with associated data (AEAD). The AEAD schemes in widespread use today (like AES-GCM) are beginning to show their age in the context of modern workloads whose scale and complexity defies assumptions made during their design over two decades ago. In the last few years, researchers and practitioners have uncovered a series of such critical limitations and responded by proposing and deploying a patchwork of fixes addressing each of these limitations in isolation. This has led to a zoo of incompatible schemes with different security properties which presents a challenge for analysis and interoperability. This thesis argues for simplifying this cluttered landscape of AEAD schemes by building a new generation of clean-slate AEAD schemes targeting modern workloads. First, we emphasize the need for new schemes by introducing new attacks. We demonstrate the first commitment attacks against CCM, EAX, and SIV, and provide more versatile attacks against GCM and OCB3. Then, we specify the first of these new schemes: a new general-purpose AEAD scheme called OCH. It is the first scheme to simultaneously achieve 128-bit multi-user AE security, 128-bit context commitment security, and 256-bit nonces with optional nonce privacy. Finally, we consider the ever-increasing list of special cases that do not admit a general-purpose AEAD scheme like OCH. Rather than specifying and analyzing a new scheme for every special case, we propose a new type of AEAD that flexibly incorporates multiple requirements simplifying analysis and usage.

Description
174 pages
Date Issued
2025-08
Keywords
Cryptography
•
Symmetric encryption
Committee Chair
Ristenpart, Thomas
Committee Member
Juels, Ari
Grimmelmann, James
Degree Discipline
Computer Science
Degree Name
Ph. D., Computer Science
Degree Level
Doctor of Philosophy
Type
dissertation or thesis

Site Statistics | Help

About eCommons | Policies | Terms of use | Contact Us

copyright © 2002-2026 Cornell University Library | Privacy | Web Accessibility Assistance