{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:18:36Z","timestamp":1781533116717,"version":"3.54.5"},"reference-count":38,"publisher":"International Association for Cryptologic Research","issue":"3","license":[{"start":{"date-parts":[[2025,7,6]],"date-time":"2025-07-06T00:00:00Z","timestamp":1751760000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372464"],"award-info":[{"award-number":["62372464"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372274"],"award-info":[{"award-number":["62372274"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202492"],"award-info":[{"award-number":["62202492"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,9,2]]},"abstract":"<jats:p>\n                    SMAC is a newly proposed MAC family built based on the finite state machine (FSM) of the SNOW-V series, targeting the high speed requirements in 5G and beyond. In this paper, we study the committing security of the SMAC family. We first theoretically reduce the committing security of SMAC to the properties of the underlying components, including the Davies-Meyer construction and the compress function. We then propose practical key-committing attacks against SMAC-1, SMAC-3\/4, and SMAC-\n                    <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                      <mml:mrow>\n                        <mml:mn>1<\/mml:mn>\n                        <mml:mi>\u00d7<\/mml:mi>\n                        <mml:mi>n<\/mml:mi>\n                      <\/mml:mrow>\n                    <\/mml:math>\n                    , as well as a theoretical attack against SMAC-1\/2 with complexity far below the birthday bound. To enhance the committing security of SMAC, we further suggest two variants of SMAC that can resist our attacks. Our results shed some light on how to design highly efficient MACs with robust committing security.\n                  <\/jats:p>","DOI":"10.62056\/avomjb0kr","type":"journal-article","created":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T18:49:52Z","timestamp":1759776592000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":0,"title":["Committing Security Analysis of SMAC"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-6581-2315","authenticated-orcid":false,"given":"Fan","family":"Yang","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/00mm1qk40","id-type":"ROR","asserted-by":"publisher"}],"name":"Information Engineering University","place":["Zhengzhou, Henan, 450000, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6044-9083","authenticated-orcid":false,"given":"Tian","family":"Tian","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/00mm1qk40","id-type":"ROR","asserted-by":"publisher"}],"name":"Information Engineering University","place":["Zhengzhou, Henan, 450000, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8520-6301","authenticated-orcid":false,"given":"Chun","family":"Guo","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0207yh398","id-type":"ROR","asserted-by":"publisher"}],"name":"Shandong University","place":["Qingdao, Shandong, 266237, China"],"department":["School of Cyber Science and Technology"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0443-8272","authenticated-orcid":false,"given":"Jing","family":"Yang","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/00mm1qk40","id-type":"ROR","asserted-by":"publisher"}],"name":"Information Engineering University","place":["Zhengzhou, Henan, 450000, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,10,6]]},"reference":[{"key":"ref1:ToSC:EJMY19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.13154\/tosc.v2019.i3.1-42","article-title":"A new SNOW stream cipher called SNOW-V","volume":"2019","author":"Patrik Ekdahl","year":"2019","journal-title":"IACR Trans. Symm. Cryptol.","ISSN":"https:\/\/id.crossref.org\/issn\/2519-173X","issn-type":"electronic"},{"key":"ref2:DBLP:conf\/wisec\/EkdahlM0Y21","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1145\/3448300.3467829","article-title":"SNOW-Vi: an extreme performance variant of SNOW-V for\n  lower grade CPUs","author":"Patrik Ekdahl","year":"2021"},{"key":"ref3:specification_11","volume-title":"S3-183756: Specification of the 256-bit air interface\n  algorithms","author":"ETSI SAGE liaison"},{"key":"ref4:DBLP:journals\/tosc\/SakamotoLNKI21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.46586\/TOSC.V2021.I2.1-30","article-title":"Rocca: An Efficient AES-based Encryption Scheme for Beyond\n  5G","volume":"2021","author":"Kosei Sakamoto","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref5:DBLP:conf\/sacrypt\/WuP13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-662-43414-7_10","article-title":"AEGIS: A Fast Authenticated Encryption Algorithm","volume":"8282","author":"Hongjun Wu","year":"2013"},{"key":"ref6:DBLP:conf\/sacrypt\/WuP16","article-title":"AEGIS: A Fast Authenticated Encryption Algorithm","author":"Hongjun Wu","journal-title":"Submission to CAESAR: Competition for Authenticated\n  Encryption. Security, Applicability, and Robustness (Round 3 and Final\n  Portfolio)"},{"key":"ref7:DBLP:journals\/SCIS\/FengJH24","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-023-3901-0","article-title":"LOL: a highly flexible framework for designing stream\n  ciphers","volume":"67","author":"Dengguo Feng","year":"2024","journal-title":"Science China Information Sciences"},{"key":"ref8:C:BHKKR99","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"216","DOI":"10.1007\/3-540-48405-1_14","article-title":"UMAC: Fast and Secure Message Authentication","volume":"1666","author":"John Black","year":"1999"},{"key":"ref9:FSE:IwaKur03","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/978-3-540-39887-5_11","article-title":"OMAC: One-Key CBC MAC","volume":"2887","author":"Tetsu Iwata","year":"2003"},{"key":"ref10:RSA:KurIwa03","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/3-540-36563-X_3","article-title":"TMAC: Two-Key CBC MAC","volume":"2612","author":"Kaoru Kurosawa","year":"2003"},{"key":"ref11:C:BlaRog00","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/3-540-44598-6_12","article-title":"CBC MACs for Arbitrary-Length Messages: The Three-Key\n  Constructions","volume":"1880","author":"John Black","year":"2000"},{"key":"ref12:JC:BlaRog05","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/s00145-004-0016-3","article-title":"CBC MACs for Arbitrary-Length Messages: The Three-Key\n  Constructions","volume":"18","author":"John Black","year":"2005","journal-title":"Journal of Cryptology"},{"key":"ref13:C:BelCanKra96","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-68697-5_1","article-title":"Keying Hash Functions for Message Authentication","volume":"1109","author":"Mihir Bellare","year":"1996"},{"key":"ref14:1250471","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.FIPS.198-1","volume-title":"The Keyed-Hash Message Authentication Code (HMAC)","author":"National Institute of Standards","year":"2008"},{"key":"ref15:FSE:DaeRij05","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11502760_1","article-title":"A New MAC Construction ALRED and a Specific Instance\n  ALPHA-MAC","volume":"3557","author":"Joan Daemen","year":"2005"},{"key":"ref16:EPRINT:DaeRij05a","volume-title":"The Pelican MAC Function 2.0","author":"Joan Daemen","year":"2005"},{"key":"ref17:FSE:BMRRT13","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1007\/978-3-662-43933-3_23","article-title":"ALE: AES-Based Lightweight Authenticated Encryption","volume":"8424","author":"Andrey Bogdanov","year":"2014"},{"key":"ref18:ToSC:BBLPPP24","doi-asserted-by":"publisher","first-page":"35","DOI":"10.46586\/tosc.v2024.i2.35-67","article-title":"Fast AES-Based Universal Hash Functions and MACs\n  Featuring LeMac and PetitMac","volume":"2024","author":"Augustin Bariant","year":"2024","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"ref19:SMAC-paper","doi-asserted-by":"publisher","first-page":"5","DOI":"10.46586\/tosc.v2025.i1.5-43","article-title":"A New Stand-Alone MAC Construct Called SMAC","volume":"2025","author":"Dachao Wang","year":"2025","journal-title":"IACR Transactions on Symmetric Cryptology"},{"key":"ref20:C:DGRW18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/978-3-319-96884-1_6","article-title":"Fast Message Franking: From Invisible Salamanders to\n  Encryptment","volume":"10991","author":"Yevgeniy Dodis","year":"2018"},{"key":"ref21:USENIX:LenGruRis21","first-page":"195","article-title":"Partitioning Oracle Attacks","author":"Julia Len","year":"2021"},{"key":"ref22:USENIX:ADGKLS22","first-page":"3291","article-title":"How to Abuse and Fix Authenticated Encryption Without Key\n  Commitment","author":"Ange Albertini","year":"2022"},{"key":"ref23:EC:BelHoa22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"845","DOI":"10.1007\/978-3-031-07085-3_29","article-title":"Efficient Schemes for Committing Authenticated Encryption","volume":"13276","author":"Mihir Bellare","year":"2022"},{"key":"ref24:C:GruLuRis17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/978-3-319-63697-9_3","article-title":"Message Franking via Committing Authenticated Encryption","volume":"10403","author":"Paul Grubbs","year":"2017"},{"key":"ref25:EC:MLGR23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"379","DOI":"10.1007\/978-3-031-30634-1_13","article-title":"Context Discovery and Commitment Attacks - How to Break\n  CCM, EAX, SIV, and More","volume":"14007","author":"Sanketh Menda","year":"2023"},{"key":"ref26:C:BirKhoNik09","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1007\/978-3-642-03356-8_14","article-title":"Distinguisher and Related-Key Attack on the Full AES-256","volume":"5677","author":"Alex Biryukov","year":"2009"},{"key":"ref27:C:BCCDGS24","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1007\/978-3-031-68385-5_14","article-title":"The Committing Security of MACs with Applications to\n  Generic Composition","volume":"14923","author":"Ritam Bhaumik","year":"2024"},{"key":"ref28:ESORICS:ChaRog22","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/978-3-031-17146-8_14","article-title":"On Committing Authenticated-Encryption","volume":"13555","author":"John Chan","year":"2022"},{"key":"ref29:bellare2023landscape","first-page":"2","article-title":"The landscape of committing authenticated encryption","author":"Mihir Bellare","year":"2023"},{"key":"ref30:NIST-3-workshop-modes","volume-title":"The third NIST workshop on block cipher modes of\n  operation","author":"National Institute of Standards","year":"2023"},{"key":"ref31:3GPP_TS_33_220_v18","volume-title":"Technical Specification Group Services and System Aspects;\n  Generic Authentication Architecture (GAA); Generic Bootstrapping\n  Architecture (GBA) (Release 18)","author":"3rd Generation Partnership Project (3GPP)","year":"2024"},{"key":"ref32:rfc2104","series-title":"Request for Comments","doi-asserted-by":"publisher","DOI":"10.17487\/RFC2104","volume-title":"HMAC: Keyed-Hashing for Message Authentication","author":"Hugo Krawczyk","year":"1997"},{"key":"ref33:secure_hash_standard","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.FIPS.180-4","volume-title":"Secure Hash Standard (SHS)","author":"National Institute of Standards","year":"2015"},{"key":"ref34:nist-sp800-108r1-upd1","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.SP.800-108r1","volume-title":"Recommendation for Key Derivation Using Pseudorandom\n  Functions","author":"Lily Chen","year":"2022"},{"key":"ref35:ToSC:DEJKLM24","doi-asserted-by":"publisher","first-page":"348","DOI":"10.46586\/tosc.v2024.i2.348-370","article-title":"Context-Committing Security of Leveled Leakage-Resilient\n  AEAD","volume":"2024","author":"Chandranan Dhar","year":"2024","journal-title":"IACR Trans. Symm. Cryptol."},{"key":"ref36:C:Merkle89b","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1007\/0-387-34805-0_40","article-title":"One Way Hash Functions and DES","volume":"435","author":"Ralph C. Merkle","year":"1990"},{"key":"ref37:C:Damgard89b","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"416","DOI":"10.1007\/0-387-34805-0_39","article-title":"A Design Principle for Hash Functions","volume":"435","author":"Ivan Damg\u00e5rd","year":"1990"},{"key":"ref38:CCS:BelJaeLen17","doi-asserted-by":"publisher","first-page":"891","DOI":"10.1145\/3133956.3134087","article-title":"Better Than Advertised: Improved Collision-Resistance\n  Guarantees for MD-Based Hash Functions","author":"Mihir Bellare","year":"2017"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T20:23:02Z","timestamp":1759782182000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/3\/22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,6]]},"references-count":38,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,10,6]]}},"URL":"https:\/\/doi.org\/10.62056\/avomjb0kr","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,6]]},"assertion":[{"value":"2025-07-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-02","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-3-38"}}