AEZ v1.1: Authenticated-Encryption by Enciphering

Viet Tung Hoang, Ted Krovetz, Sacramento State, Phillip Rogaway · 2014

The named authors are both designers and submitters. AEZ encrypts by appending to the plaintext a fixed authentication block and then enciphering the resulting string with an arbitrary-input-length blockcipher, this tweaked by the nonce and AD. The approach results in strong security and usability properties, including nonce-reuse security, automatic exploitation of decryption-verified redundancy, and arbitrary, user-selectable length expansion. AEZ is parallelizable and its computational cost is roughly 1.8 times that of AES-CTR. On recent Intel processors, AEZ runs at about 1.4 cpb on 2 KB messages. The latest version of this document, and any other related material, can be found on the AEZ

Read the paper · More papers on PaperTik