{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:06:53Z","timestamp":1760242013428,"version":"build-2065373602"},"reference-count":19,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2018,12,4]],"date-time":"2018-12-04T00:00:00Z","timestamp":1543881600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>A technique of authenticated encryption for memory constrained devices called sp-AELM was proposed by Agrawal et al. at ACISP 2015. The sp-ALEM construction utilizes a sponge-based primitive to support online encryption and decryption functionalities. Online encryption in the construction is achieved in the standard manner by processing plaintext blocks as they arrive to produce ciphertext blocks. However, decryption is achieved by storing only one intermediate state and releasing it to the user upon correct verification. This intermediate state allows a legitimate user to generate the plaintext herself. However, the scheme is nonce-respecting, i.e., the scheme is insecure if the nonce is repeated. Implementation of a nonce is non-trivial in practice, and reuse of a nonce in an AE scheme is often devastating. In this paper, we propose a new AE scheme called dAELM, which stands for deterministic authenticated encryption (DAE) scheme for low memory devices. DAE is used in domains such as the key wrap, where the available message entropy omits the overhead of a nonce. For limiting memory usage, our idea is to use a session key to encrypt a message and share the session key with the user depending upon the verification of a tag. We provide the security proof of the proposed construction in the ideal cipher model.<\/jats:p>","DOI":"10.3390\/cryptography2040037","type":"journal-article","created":{"date-parts":[[2018,12,4]],"date-time":"2018-12-04T11:56:18Z","timestamp":1543924578000},"page":"37","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Deterministic Authenticated Encryption Scheme for Memory Constrained Devices"],"prefix":"10.3390","volume":"2","author":[{"given":"Megha","family":"Agrawal","sequence":"first","affiliation":[{"name":"Indraprastha Institute of Information Technology, Delhi 110020, Indian"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Donghoon","family":"Chang","sequence":"additional","affiliation":[{"name":"Indraprastha Institute of Information Technology, Delhi 110020, Indian"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinkeon","family":"Kang","sequence":"additional","affiliation":[{"name":"Indraprastha Institute of Information Technology, Delhi 110020, Indian"},{"name":"Center for Information Security Technologies (CIST), Korea University, Seoul 02841, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2018,12,4]]},"reference":[{"key":"ref_1","unstructured":"(2018, November 30). CAESAR: Competition for Authenticated Encryption: Security, Applicability, and Robustness. Available online: http:\/\/competitions.cr.yp.to\/caesar.html."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"469","DOI":"10.1007\/s00145-008-9026-x","article-title":"Authenticated Encryption: Relations Among Notions and Analysis of the Generic Composition Paradigm","volume":"21","author":"Bellare","year":"2008","journal-title":"J. Cryptol."},{"key":"ref_3","first-page":"317","article-title":"Encode-Then-Encipher Encryption: How to Exploit Nonces or Redundancy in Plaintexts for Efficient Cryptography","volume":"Volume 1976","author":"Okamoto","year":"2000","journal-title":"ASIACRYPT"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"529","DOI":"10.1007\/3-540-44987-6_32","article-title":"Encryption Modes with Almost Free Message Integrity","volume":"Volume 2045","author":"Pfitzmann","year":"2001","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2001"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1145\/937527.937529","article-title":"OCB: A block-cipher mode of operation for efficient authenticated encryption","volume":"6","author":"Rogaway","year":"2003","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Rogaway, P. (2002, January 18\u201322). Authenticated-encryption with associated-data. Proceedings of the 9th ACM Conference on Computer and Communications Security, CCS 2002, Washington, DC, USA.","DOI":"10.1145\/586110.586125"},{"key":"ref_7","first-page":"92","article-title":"Fast Encryption and Authentication: XCBC Encryption and XECB Authentication Modes","volume":"Volume 2355","author":"Matsui","year":"2001","journal-title":"Fast Software Encryption"},{"key":"ref_8","first-page":"221","article-title":"Deterministic Authenticated-Encryption: A Provable-Security Treatment of the Key-Wrap Problem","volume":"Volume 2006","author":"Rogaway","year":"2006","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2006"},{"key":"ref_9","first-page":"145","article-title":"Authenticated On-Line Encryption","volume":"Volume 3006","author":"Matsui","year":"2003","journal-title":"Selected Areas in Cryptography"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"451","DOI":"10.1007\/978-3-319-19962-7_26","article-title":"sp-AELM: Sponge Based Authenticated Encryption Scheme for Memory Constrained Devices","volume":"Volume 9144","author":"Foo","year":"2015","journal-title":"Information Security and Privacy"},{"key":"ref_11","first-page":"19","article-title":"The Hummingbird-2 Lightweight Authenticated Encryption Algorithm","volume":"Volume 7055","author":"Juels","year":"2011","journal-title":"RFID, Security and Privacy"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Moriai, S. (2014). ALE: AES-Based Lightweight Authenticated Encryption. Fast Software Encryption, Springer.","DOI":"10.1007\/978-3-662-43933-3"},{"key":"ref_13","unstructured":"Dobraunig, C., Eichlseder, M., Mendel, F., and Schlaffer, M. (2018, November 30). Ascon v1. Available online: http:\/\/competitions.cr.yp.to\/round1\/asconv1.pdf."},{"key":"ref_14","unstructured":"Aumasson, J.P., and Philipp Jovanovic, S.N. (2018, November 30). NORX: Parallel and Scalable AEAD. Available online: https:\/\/norx.io\/."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Bertoni, G., Daemen, J., Peeters, M., van Assche, G., and van Keer, R. (2018, November 30). Ketje v1. Available online: http:\/\/competitions.cr.yp.to\/round1\/ketjev11.pdf.","DOI":"10.46586\/tosc.v2017.i4.1-38"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1186","DOI":"10.1002\/sec.1410","article-title":"PFX: An essence of authencryption for block-cipher security","volume":"9","author":"Hwang","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"3939","DOI":"10.1002\/sec.1312","article-title":"IAR-CTR and IAR-CFB: Integrity aware real-time based counter and cipher feedback modes","volume":"8","author":"Hwang","year":"2015","journal-title":"Secur. Commun. Netw."},{"key":"ref_18","unstructured":"Gennaro, R., and Robshaw, M. (2015). Online Authenticated-Encryption and its Nonce-Reuse Misuse-Resistance. Advances in Cryptology\u2014CRYPTO 2015, Springer."},{"key":"ref_19","first-page":"331","article-title":"Code-Based Game-Playing Proofs and the Security of Triple Encryption","volume":"Volume 2004","author":"Bellare","year":"2006","journal-title":"Advances in Cryptology\u2014Eurocrypt 2006"}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/2\/4\/37\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T15:31:07Z","timestamp":1760196667000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/2\/4\/37"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,4]]},"references-count":19,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2018,12]]}},"alternative-id":["cryptography2040037"],"URL":"https:\/\/doi.org\/10.3390\/cryptography2040037","relation":{},"ISSN":["2410-387X"],"issn-type":[{"type":"electronic","value":"2410-387X"}],"subject":[],"published":{"date-parts":[[2018,12,4]]}}}