On Message Integrity in Symmetric Encryption
Virgil D. Gligor, Pompiliu Donescu · 2000
Distinct notions of message integrity (authenticity) for block-oriented symmetric encryption are defined by integrity goals to be achieved in the face of different types of attacks. These notions are partially ordered by a "dominance" relation. When chosen-plaintext attacks are considered, most integrity goals form a lattice. The lattice is extended when known-plaintext and ciphertext-only attacks are also included. The practical use of the dominance relation and lattice in defining the relative strength of different integrity notions is illustrated with common modes of encryption, such as the "infinite garble extension" modes, and simple, non-cryptographic, manipulation detection code functions, such as bitwise exclusive-or and constant functions. 1 Introduction The fact that encryption does not provide message integrity (authenticity) is generally well-understood [17], and so is the fact that often "encryption without integrity-checking is all but useless" [7]. Less wellunderstood i...