Encrypt-Then-Mac for Committing AEAD (CAEAD) Internet Draft
samuellucas.com
samuellucas.com
1. It explains how to construct an AEAD scheme by combining an unauthenticated cipher and collision-resistant, hash-based MAC. To my knowledge, this has not been written up before. It's important because it's more flexible than regular Encrypt-then-MAC without associated data and provides a standardised approach for implementation.
2. AEAD schemes like AES-GCM, ChaCha20-Poly1305, and AES-OCB aren't committing. A committing scheme is required in some scenarios (e.g. password-based encryption) and should really be the default to prevent attacks.
3. There still seems to be a lack of awareness that AEADs are not committing. This attempts to summarise what it means since the topic is confusing.
Any feedback would be much appreciated.