1 research outputs found

    On the security margin of MAC striping

    Get PDF
    MAC striping has been suggested as a technique to authenticate encrypted payloads using short tags. For an idealized MAC scheme, the probability of a selective forgery has been estimated as (β„“+mm)βˆ’1β‹…2βˆ’m\binom{\ell+m}{m}^{-1}\cdot 2^{-m}, when utilizing MAC striping with β„“\ell-bit payloads and mm-bit tags. We show that this estimate is too optimistic. For m≀ℓm\le\ell and any payload, we achieve a selective forgery with probability β‰₯(β„“+mm)βˆ’1\ge \binom{\ell+m}{m}^{-1}, and usually many orders of magnitude more than that
    corecore