Learning path

Full curriculum

Full curriculum

Unit content

Authenticated encryption

Practical encrypted communication usually needs both confidentiality and integrity.

An authenticated-encryption scheme encrypts a plaintext and also produces an authentication tag. A common interface is

$$ (c,t)=E_k(n,m,a), $$

where $n$ is a nonce, $m$ is the plaintext and $a$ is associated data that is authenticated but not encrypted.

Decryption returns the plaintext only if the tag verifies. Modified ciphertext, nonce or associated data should cause verification failure rather than produce unauthenticated plaintext.

Associated data is useful for fields that must remain visible for routing or framing but must not be changed silently.

Authenticated encryption with associated data (AEAD) avoids treating encryption and integrity as unrelated afterthoughts. It also makes nonce requirements part of the construction: reusing a nonce in a scheme that requires uniqueness can seriously compromise confidentiality or integrity.

Applications should normally use a well-reviewed authenticated-encryption construction rather than inventing their own combination of cipher and authentication mechanism.