Research Article

Close to Optimally Secure Variants of GCM

Table 1

Comparisons among AES-GCM [34], AES-OGCM-1, and AES-OGCM-2. The nonce length is restricted to 96 bits. “n.r.” denotes nonce-respecting. “” means can be reduced to . Let be the block length of the plaintext and be the block length of associated data.

AES-GCM [34]AES-OGCM-1AES-OGCM-2

# keys1
CTR-likeYesYesYes
Block size 128128128
Nonce scenarion.r.n.r.n.r.
AssumptionPRPPRPPRP
Security (bits)64107.9565121.9339
# block cipher calls
# multiplications