The Power of Verification Queries in Message Authentication and Authenticated Encryption.

Mihir Bellare, Oded Goldreich, Anton Mityagin · 2004

This paper points out that, contrary to popular belief, allowing a message authentication adversary multiple verification attempts towards forgery is not equivalent to allowing it a single one, so that the notion of security that most message authentication schemes are proven to meet does not guarantee their security in practice. We then show, however, that the equivalence does hold for strong unforgeability. Based on this we recover security of popular classes of message authentication schemes such as MACs (including HMAC and PRF-based MACs) and CWschemes.

Read the paper · More papers on PaperTik