{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T13:01:22Z","timestamp":1784638882524,"version":"3.55.0"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032325594","type":"print"},{"value":"9783032325600","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T00:00:00Z","timestamp":1784678400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T00:00:00Z","timestamp":1784678400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-32560-0_8","type":"book-chapter","created":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T12:04:22Z","timestamp":1784635462000},"page":"211-240","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Tight Multi-user Security of CCM and Enhancement by Tag-Based Key Derivation"],"prefix":"10.1007","author":[{"given":"Yusuke","family":"Naito","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Sasaki","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Takeshi","family":"Sugawara","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,22]]},"reference":[{"key":"8_CR1","doi-asserted-by":"crossref","unstructured":"Bellare, M., Pietrzak, K., Rogaway, P.: Improved security analyses for CBC MACs. In: CRYPTO 2005. LNCS, vol. 3621, pp. 527\u2013545. Springer (2005)","DOI":"10.1007\/11535218_32"},{"key":"8_CR2","doi-asserted-by":"crossref","unstructured":"Bellare, M., Tackmann, B.: The multi-user security of authenticated encryption: AES-GCM in TLS 1.3. In: CRYPTO 2016. LNCS, vol. 9814, pp. 247\u2013276. Springer (2016)","DOI":"10.1007\/978-3-662-53018-4_10"},{"issue":"3","key":"8_CR3","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1016\/S0020-0190(02)00269-7","volume":"84","author":"E Biham","year":"2002","unstructured":"Biham, E.: How to decrypt or even substitute DES-encrypted messages in $$2^{28}$$ steps. Inf. Process. Lett. 84(3), 117\u2013124 (2002)","journal-title":"Inf. Process. Lett."},{"key":"8_CR4","first-page":"1","volume":"5282","author":"DL Black","year":"2008","unstructured":"Black, D.L., McGrew, D.A.: Using authenticated encryption algorithms with the encrypted payload of the internet key exchange version 2 (IKEv2) protocol. RFC 5282, 1\u201319 (2008)","journal-title":"RFC"},{"key":"8_CR5","doi-asserted-by":"crossref","unstructured":"Bose, P., Hoang, V.T., Tessaro, S.: Revisiting AES-GCM-SIV: multi-user security, faster key derivation, and better bounds. In: EUROCRYPT 2018. LNCS, vol. 10820, pp. 468\u2013499 (2018)","DOI":"10.1007\/978-3-319-78381-9_18"},{"key":"8_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"754","DOI":"10.1007\/978-3-030-64837-4_25","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"B Cogliati","year":"2020","unstructured":"Cogliati, B., Jha, A., Nandi, M.: How to build optimally secure PRFs using block ciphers. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12491, pp. 754\u2013784. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_25"},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"Degabriele, J.P., Govinden, J., G\u00fcnther, F., Paterson, K.G.: The security of ChaCha20-Poly1305 in the multi-user setting. In: CCS 2021, pp. 1981\u20132003. ACM (2021)","DOI":"10.1145\/3460120.3484814"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"Dworkin, M.: NIST Special Publication 800-38C: Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality (2007). https:\/\/csrc.nist.gov\/pubs\/sp\/800\/38\/c\/upd1\/final","DOI":"10.6028\/NIST.SP.800-38c"},{"key":"8_CR9","doi-asserted-by":"crossref","unstructured":"Dworkin, M.: NIST Special Publication 800-38D: Recommendation for Block Cipher Modes of Operation: Galois\/Counter Mode (GCM) and GMAC (2007). https:\/\/csrc.nist.gov\/pubs\/sp\/800\/38\/d\/final","DOI":"10.6028\/NIST.SP.800-38d"},{"key":"8_CR10","doi-asserted-by":"crossref","unstructured":"Dworkin, M.: NIST Special Publication 800-38B: Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication (2016). https:\/\/csrc.nist.gov\/pubs\/sp\/800\/38\/b\/upd1\/final","DOI":"10.6028\/NIST.SP.800-38b"},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"Gueron, S., Lindell, Y.: Better bounds for block cipher modes of operation via nonce-based key derivation. In: CCS 2017, pp. 1019\u20131036. ACM (2017)","DOI":"10.1145\/3133956.3133992"},{"key":"8_CR12","unstructured":"G\u00fcnther, F., Thomson, M., Wood, C.A.: Usage Limits on AEAD Algorithms (2023). https:\/\/datatracker.ietf.org\/doc\/html\/draft-irtf-cfrg-aead-limits-07"},{"key":"8_CR13","doi-asserted-by":"crossref","unstructured":"Hoang, V.T., Tessaro, S., Thiruvengadam, A.: The multi-user security of GCM, revisited: tight bounds for nonce randomization. In: CCS 2018, pp. 1429\u20131440. ACM (2018)","DOI":"10.1145\/3243734.3243816"},{"key":"8_CR14","doi-asserted-by":"crossref","unstructured":"Housley, R.: Using advanced encryption standard (AES) CCM mode with IPSec encapsulating security payload (ESP). RFC 4309, 1\u201313 (2005)","DOI":"10.17487\/rfc4309"},{"key":"8_CR15","unstructured":"ISO: ISO\/IEC 19772:2020 information security\u2014authenticated encryption (2020)"},{"key":"8_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1007\/11799313_20","volume-title":"Fast Software Encryption","author":"T Iwata","year":"2006","unstructured":"Iwata, T.: New blockcipher modes of operation with beyond the birthday bound security. In: Robshaw, M. (ed.) FSE 2006. LNCS, vol. 4047, pp. 310\u2013327. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11799313_20"},{"key":"8_CR17","doi-asserted-by":"crossref","unstructured":"Jonsson, J.: On the security of CTR + CBC-MAC. In: Selected Areas in Cryptography, SAC 2002. LNCS, vol.\u00a02595, pp. 76\u201393. Springer (2002)","DOI":"10.1007\/3-540-36492-7_7"},{"key":"8_CR18","unstructured":"Kampanakis, P., Campagna, M., Crocket, E., Petcher, A.: Practical challenges with AES-GCM and the need for a new mode and wide-block cipher. Presented at NIST The Third NIST Workshop on Block Cipher Modes of Operation 2023 (2023). https:\/\/csrc.nist.gov\/Presentations\/2023\/practical-challenges-with-aes-gcm"},{"key":"8_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"575","DOI":"10.1007\/978-3-319-70697-9_20","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"A Luykx","year":"2017","unstructured":"Luykx, A., Mennink, B., Paterson, K.G.: Analyzing multi-key security degradation. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 575\u2013605. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_20"},{"key":"8_CR20","first-page":"1","volume":"6655","author":"DA McGrew","year":"2012","unstructured":"McGrew, D.A., Bailey, D.V.: AES-CCM cipher suites for transport layer security (TLS). RFC 6655, 1\u20138 (2012)","journal-title":"RFC"},{"issue":"2","key":"8_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.46586\/tosc.v2017.i2.1-26","volume":"2017","author":"Y Naito","year":"2017","unstructured":"Naito, Y.: Tweakable blockciphers for efficient authenticated encryptions with beyond the birthday-bound security. IACR Trans. Symmetric Cryptol. 2017(2), 1\u201326 (2017)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"Naito, Y., Sasaki, Y., Sugawara, T.: Tight multi-user security of CCM and enhancement by tag-based key derivation applied to GCM and CCM. IACR Cryptol. ePrint Arch. 953 (2025)","DOI":"10.1007\/978-3-032-08124-7_3"},{"key":"8_CR23","unstructured":"National Institute of Standards and Technology: Pre-Draft Call for Comments: GCM and GMAC Block Cipher Modes of Operation (2025). https:\/\/csrc.nist.gov\/pubs\/sp\/800\/38\/d\/r1\/iprd"},{"key":"8_CR24","unstructured":"NIST: Fips pub. 198-1: The keyed-hash message authentication code (HMAC) (2008). https:\/\/nvlpubs.nist.gov\/nistpubs\/FIPS\/NIST.FIPS.198-1.pdf"},{"key":"8_CR25","unstructured":"NIST: Fips pub. 202: Sha-3 standard: Permutation-based hash and extendable-output functions) (2015). https:\/\/nvlpubs.nist.gov\/nistpubs\/FIPS\/NIST.FIPS.202.pdf"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"Rescorla, E.: The Transport Layer Security (TLS) Protocol Version 1.3. RFC, vol. 8446, pp. 1\u2013160 (2018)","DOI":"10.17487\/RFC8446"},{"key":"8_CR27","doi-asserted-by":"crossref","unstructured":"Rescorla, E., Tschofenig, H., Modadugu, N.: The Datagram Transport Layer Security (DTLS) Protocol Version 1.3 \u2013 draft-ietf-tls-dtls13-43 (2021). https:\/\/tools.ietf.org\/html\/draft-ietf-tls-dtls13-43","DOI":"10.17487\/RFC9147"},{"key":"8_CR28","unstructured":"Rogaway, P., Wagner, D.A.: A Critique of CCM. Cryptology ePrint Archive, Paper 2003\/070 (2003)"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Salowey, J.A., McGrew, D., Choudhury, A.: AES Galois counter mode (GCM) cipher suites for TLS. RFC 5288, 1\u20138 (2008)","DOI":"10.17487\/rfc5288"},{"key":"8_CR30","unstructured":"Seaman, M.: IEEE Standard for Local and Metropolitan Area Networks\u2014Media Access Control (MAC) Security (2018). https:\/\/ieeexplore.ieee.org\/document\/8585421"},{"key":"8_CR31","first-page":"1","volume":"9001","author":"M Thomson","year":"2021","unstructured":"Thomson, M., Turner, S.: Using TLS to secure QUIC. RFC 9001, 1\u201352 (2021)","journal-title":"RFC"},{"key":"8_CR32","first-page":"1","volume":"4543","author":"J Viega","year":"2006","unstructured":"Viega, J., McGrew, D.: The use of galois message authentication code (GMAC) in IPsec ESP and AH. RFC 4543, 1\u201314 (2006)","journal-title":"RFC"},{"key":"8_CR33","unstructured":"Whiting, D., Housley, R., Ferguson, N.: IEEE P802.11 Wireless LANs: AES Encryption & Authentication Using CTR Mode & CBC-MAC (2002). https:\/\/mentor.ieee.org\/802.11\/dcn\/02\/11-02-0001-02-000i-aes-encryption-authentication-using-ctr-mode-with-cbc-mac.doc"},{"key":"8_CR34","first-page":"1","volume":"3610","author":"D Whiting","year":"2003","unstructured":"Whiting, D., Housley, R., Ferguson, N.: Counter with CBC-MAC (CCM). RFC 3610, 1\u201326 (2003)","journal-title":"RFC"},{"key":"8_CR35","unstructured":"Wi-Fi Alliance: WPA3 Specification Version 3.2 (2023). https:\/\/www.wi-fi.org\/system\/files\/WPA3%20Specification%20v3.2.pdf"},{"key":"8_CR36","unstructured":"Woolley, M.: Bluetooth core specification version, vol. 5, p. 4 (2023)"},{"key":"8_CR37","doi-asserted-by":"crossref","unstructured":"Zhang, X., Shen, Y., Wang, L.: Multi-user security of CCM authenticated encryption mode. In: CCS 2024, pp. 4331\u20134345. ACM (2024)","DOI":"10.1145\/3658644.3670385"},{"key":"8_CR38","unstructured":"ZigBee Alliance, Inc.: Zigbee specification (2015). https:\/\/zigbeealliance.org\/wp-content\/uploads\/2019\/11\/docs-05-3474-21-0csg-zigbee-specification.pdf"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-32560-0_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T12:04:30Z","timestamp":1784635470000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-32560-0_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,22]]},"ISBN":["9783032325594","9783032325600"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-32560-0_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,22]]},"assertion":[{"value":"22 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Stony Brook, WI","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 June 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 June 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/acns2026.github.io\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}