Reconsidering Generic Composition

  title={Reconsidering Generic Composition},
  author={Chanathip Namprempre and Phillip Rogaway and Thomas Shrimpton},
  journal={IACR Cryptology ePrint Archive},
In the context of authenticated encryption (AE), generic composition has referred to the construction of an AE scheme by gluing together a conventional (privacy-only) encryption scheme and a MAC. Since the work of Bellare and Namprempre (2000) and then Krawczyk (2001), the conventional wisdom has become that there are three forms of generic composition, with Encrypt-then-MAC the only one that generically works. However, many caveats to this understanding have surfaced over the years. Here we… CONTINUE READING
47 Citations
16 References
Similar Papers


Publications citing this paper.
Showing 1-10 of 47 extracted citations


Publications referenced by this paper.
Showing 1-10 of 16 references


  • FIPS Publicatio
  • DES modes of operation. National Institute of…
  • 1980
Highly Influential
5 Excerpts

Reconsidering generic composition

  • C. Namprempre, P. Rogaway, T. Shrimpton
  • Cryptology ePrint Archive, Report 2014/xxx,
  • 2014
1 Excerpt

Insecurity of MtE (and M&E) AEAD

  • M. Bellare, B. Tackmann
  • Personal communications (unpublished note), July
  • 2013
3 Excerpts

Recommendation for block cipher modes of operation: Galois/counter mode (GCM) and GMAC

  • M. Dworkin
  • NIST Special Publication 800-38D, Nov
  • 2007
1 Excerpt

Recommendation for block cipher modes of operation: The CCM mode for authentication and confidentiality

  • M. Dworkin
  • NIST Special Publication 800-38C, May
  • 2004
1 Excerpt

Similar Papers

Loading similar papers…