Message Authentication and Authenticated Encryption
Tetsu Iwata · 2023
This chapter considers the provable security of message authentication and authenticated encryption. It formalizes a message authentication code and discusses the security definition. The chapter introduces a universal hash function and shows an example of the provable security result of Wegman-Carter-Shoup authenticator. It considers authenticated encryption and shows an example of the provable security result of Galois/counter mode (GCM). A message authentication code (MAC) is used to ensure data integrity, that is, it is used to detect possibly malicious manipulation of messages during their transmission. There are several types of security definitions for MACs. In many use cases of a symmetric key cryptosystem, we often want to encrypt and authenticate data, and authenticated encryption can be used to efficiently achieve the goal. GCM is a nonce-based authenticated encryption with associated data scheme.