Transactions on Cryptographic Hardware and Embedded Systems 2025
Cymric: Short-tailed but Mighty:
Beyond-birthday-bound Secure Authenticated Encryption for Short Inputs
Alexandre Adomnicăi
Independent Researcher, Paris, France
Wonseok Choi
Purdue University, West Lafayette, US; Georgia Institute of Technology, Atlanta, US
Yeongmin Lee
DESILO Inc., Seoul, Korea
Kazuhiko Minematsu
NEC, Kawasaki, Japan
Yusuke Naito
Mitsubishi Electric Corporation, Kanagawa, Japan
Keywords: Authenticated Encryption, Short input, Beyond birthday bound security
Abstract
Authenticated encryption (AE) is a fundamental tool in today’s secure communication. Numerous designs have been proposed, including well-known standards such as GCM. While their performance for long inputs is excellent, that for short inputs is often problematic due to high overhead in computation, showing a gap between the real need for IoT-like protocols where packets are often very short. Existing dedicated short-input AEs are very scarce, the classical Encode-then-encipher (Bellare and Rogaway, Asiacrypt 2000) and Manx (Adomnicăi et al., CT-RSA 2023), using up to two block cipher calls. They have superior performance for (very) short inputs, however, security is up to n/2 bits, where n is the block size of the underlying block cipher. This paper proposes a new family of short-input AEs, dubbed Cymric, which ensure beyond-birthday-bound (BBB) security. It supports a wider range of input space than EtE and Manx with the help of one additional block cipher call (thus three calls). In terms of the number of block cipher calls, Cymric is the known minimum construction of BBB-secure AEs, and we also prove this is indeed minimal by presenting an impossibility result on BBB-secure AE with two calls. Finally, we show a comprehensive benchmark on microcontrollers to show performance advantage over existing schemes.
Publication
IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2025, Issue 3
PaperArtifact
Artifact number
tches/2025/a31
Artifact published
September 1, 2025
Badge
✅ IACR CHES Artifacts Functional
License
To the extent possible under law, the author(s) have waived all copyright and related or neighboring rights to this artifact.
Some files in this archive are licensed under a different license. See the contents of this archive for more information.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Alexandre Adomnicăi, Wonseok Choi, Yeongmin Lee, Kazuhiko Minematsu, Yusuke Naito. (2025). Cymric: Short-tailed but Mighty: Beyond-birthday-bound Secure Authenticated Encryption for Short Inputs. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025(3), 437–469. https://doi.org/10.46586/tches.v2025.i3.437-469. Artifact at https://artifacts.iacr.org/tches/2025/a31.