Improved security analysis for OMAC as a pseudorandom function

Mridul Nandi · Journal of Mathematical Cryptology · 2009

Abstract This paper shows that the advantage of any q -query adversary (which makes at most q queries) for distinguishing OMAC from a uniform random function is roughly Lq 2 /2 n . Here L is the number of blocks of the longest query and n is the output size of the uniform random function. The so far best bound is roughly σ 2 /2 n = O( L 2 q 2 /2 n ) and hence our new bound is an improved bound. Our improved security analysis also works for OMAC1 and CMAC which has been recommended by NIST as a candidate of blockcipher based MAC.

Read the paper · More papers on PaperTik