International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Cryptanalysis of OCB2: the attacks and the story behind

Authors:
Kazuhiko Minematsu , NEC
Download:
Search ePrint
Search Google
Honor: Invited talk
Abstract: I will talk about OCB2, an authenticated encryption (AE) mode of operation proposed at 2004. It is a very popular scheme for its innovative design. The tweakable block cipher-based modular architecture of OCB2 was influenced to countless subsequent schemes. However, our paper presented at CRYPTO 2019 showed that it is completely broken with negligible amount of computation. In addition to the description of our attacks, I will tell a bit more on the story behind this break, how it started and evolved, hoping that it contributes to our understanding of practical provable security.
Video from FSE 2020
BibTeX
@misc{fse-2020-31303,
  title={Cryptanalysis of OCB2: the attacks and the story behind},
  note={Invited talk},
  author={Kazuhiko Minematsu},
  year=2020
}