Research Article

Close to Optimally Secure Variants of GCM

Table 2

Comparison of AE schemes that provide BBB security. “” means can be reduced to . “n.r.” denotes nonce-respecting and “n.m.” denotes nonce-misuse. “PRP” stands for pseudorandom permutation, “TPRP” stands for tweakable PRP, and “PRF” stands for pseudorandom function. Let be the block length of the plaintext and be the block length of associated data. Let be two integers. Let stand for approximately equal to. For example, 128 means that it is approximately equal to 128.

CHMGCM-SIVrOGCM-1OGCM-2SCTSIVxRWCTRN

# keys111
Nonce scenarion.r.n.m.n.r.n.r.n.m.n.m.n.r.
AssumptionPRPPRPPRPPRPTPRPTPRPPRF
Block size 128128128128128128256
Security (bits)85.3333128128248
# primitive Calls
# multiplications00
Reference[30][32]This paperThis paper[12][11][47]