[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-159045-105":59,"doc-detail-159045-en":131},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":124,"head_meta":126,"extra_data":128,"updated_unix":130},105,"en","paes-v1-parallelizable-authenticated-encryption-schemes-based-on-aes-round-function","PAES v1 - Parallelizable Authenticated Encryption Schemes based on AES Round Function","","Authenticated encryption provides confidentiality and integrity at once, preventing an adversary from learning anything beyond plaintext length while ensuring ciphertext authenticity and resistance to tampering. This work presents PAES, a parallelizable authenticated encryption family (PAES-4 and PAES-8) constructed using the AES round function. The document specifies encryption and decryption algorithms, formalizes security goals, and provides security analysis via linear and differential approaches. Design rationale and intellectual property and consent notes complete the package.",{"@graph":69,"@context":123},[70,84,106],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/paes-v1-parallelizable-authenticated-encryption-schemes-based-on-aes-round-function/159045/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/paes-v1-parallelizable-authenticated-encryption-schemes-based-on-aes-round-function/159045.png","ImageObject",300,407,{"name":92,"@type":93},"Felix Montgomery","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-10-05","2026-08-29",true,{"@type":102,"interactionType":103,"userInteractionCount":105},"InteractionCounter",{"@type":104},"ViewAction",12,{"@type":107,"mainEntity":108},"FAQPage",[109,115,119],{"name":110,"@type":111,"acceptedAnswer":112},"What problem does authenticated encryption address in this document?","Question",{"text":113,"@type":114},"It simultaneously provides confidentiality (hiding plaintext information except length) and integrity (ensuring ciphertext is authentic and unmodified during transmission).","Answer",{"name":116,"@type":111,"acceptedAnswer":117},"How are PAES-4 and PAES-8 constructed and what differs between them?",{"text":118,"@type":114},"Both are based on the AES round function. They differ in state size: PAES-4 uses four blocks, while PAES-8 uses eight blocks, targeting extra robustness in nonce-repeating scenarios.",{"name":120,"@type":111,"acceptedAnswer":121},"What security analysis methods are included?",{"text":122,"@type":114},"The paper includes linear analysis and differential analysis, supported by AES properties such as the number of active S-boxes over several rounds.","https://schema.org",{"og:url":83,"og:type":125,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":127,"canonical":83},"index,follow",{"doc_id":129,"site_id":62},159045,1788011342,{"code":4,"msg":5,"data":132},{"doc_id":129,"user_id":133,"nickname":92,"user_avatar":134,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":135,"file_id":136,"file_url":137,"file_type":138,"file_size":139,"view_count":105,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":140,"language":141,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":142,"faqs":143,"seo_title":144,"seo_description":67,"update_tm":130,"read_time":145},549768064778,"https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8","PAES v1:  \nParallelizable Authenticated Encryption Schemes based on AES Round Function  \nDesigners and submtters:  \nDingfeng Ye, Peng Wang, Lei Hu, Liping Wang, Yonghong Xie, Siwei Sun, Ping Wang  \nInstitute of Information engineering Chinese Academy of Sciences  \n[wp@is.ac.cn](wp@is.ac.cn)  \nMarch 15, 2014  \nContents  \n1 Introduction 1  \n2 Speciﬁcation of PAES 3  \n2.1 Speciﬁcation of PAES-4 ....................................... 3  \n2.1.1 State update functions of PAES-4 ............................. 3  \n2.1.2 The encryption: PAES-4.EncK (N; A; P ) .......................... 4  \n2.1.3 The decryption: PAES-4.DecK (N; A; C; T ) ........................ 5  \n2.2 Speciﬁcation of PAES-8 ....................................... 5  \n2.2.1 State update functions of PAES-8 ............................. 5  \n2.2.2 The encryption: PAES-8.EncK (N; A; P ) .......................... 6  \n2.2.3 The decryption: PAES-8.DecK (N; A; C; T ) ........................ 7  \n3 Security goals 8  \n4 Security analysis 10  \n4.1 Linear analysis ........................................... 10  \n4.2 Differential analysis ........................................ 12  \n5 Features 14  \n6 Design rationale 15  \n7 Intellectual property 16  \n8 Consent 17  \nChapter 1  \nIntroduction  \nAuthenticated encryption, AE for short, is a symmetric cryptographic primitive that provides protections for conﬁdentiality and integrity (authentication) simultaneously. Simply speaking, conﬁdentiality guarantees that an adversary can not get any information (except the length) about the plaintext from the ciphertext, whilst integrity guarantees that the ciphertext is truly delivered from the sender and not modiﬁed by an adversary during transmission.  \nAn AE scheme can be based on some cryptographic components, such as a block cipher, a stream cipher combined with a MAC (e.g., Grain-128a [1], 128-EIA3 [10]), or a permutation in sponge structure (e.g., FIDES [3], APE [2]) . The most popular approach to construct AE is to use a block cipher in a mode. The advantage of this approach is that we can prove the security of the mode in some adversarial model, given that the underlying block cipher is secure, e.g., it is a pseudorandom permutation (PRP) . A large number of AE modes have been proposed and standardized, such as OCB [17], GCM [16], CCM [19], SIV [18] . Although efﬁcient AE modes, such as OCB, can get both conﬁdentiality and integrity by processing messages in only one-pass, they still need one block cipher-invocation per message-block. Furthermore, almost all the modes suffer from birthday attacks which reduce the bits of security from n in block cipher to n=2 . It is not big deal for 128-bit block cipher modes, but for 64-bit modes, 32-bit strength is so weak that it is allowed to a practical attack.  \nThe other approach to construct AE is to use the component of block cipher such as AES round function, which is also used in other schemes, for example, message authentication code Pelican [9] and stream cipher LEX [4] . The existing constructions of AE in this way include ACS-1 [14], ALE [5], Marvin [15], and AEGIS [20, 21] . Although all these schemes lack provable security against general attacks such as chosen plaintext/ciphertext attacks (CPA/CCA) as the above modes, the demonstration of security against some speciﬁc attacks such as linear/differential attacks is straightforward by utilizing some AES properties, for instance, the number of active S-boxes of four-round AES is at lest 25.  \nMoreover, a set of new instructions AES-NI (Advanced Encryption Standard New Instructions) is supported in recent years, ﬁrst by Intel CPU and then by AMD CPU. AES-NI has six instructions: four instructions for the AES round functions, and the other two for the AES key expansion. These instructions greatly improve the software performance of AES, its modes, and the schemes based on the AES round function.  \nAEGIS is the fastest AE scheme so far due to its parallel structure. There are three versi","cbCaitebGTRW0wpg","https://ap.wps.com/l/cbCaitebGTRW0wpg","pdf",853603,22,"English","# Introduction\n# Specification of PAES\n## Specification of PAES-4\n## Specification of PAES-8\n# Security goals\n# Security analysis\n## Linear analysis\n## Differential analysis\n# Features\n# Design rationale\n# Intellectual property\n# Consent","[{\"question\":\"What problem does authenticated encryption address in this document?\",\"answer\":\"It simultaneously provides confidentiality (hiding plaintext information except length) and integrity (ensuring ciphertext is authentic and unmodified during transmission).\"},{\"question\":\"How are PAES-4 and PAES-8 constructed and what differs between them?\",\"answer\":\"Both are based on the AES round function. They differ in state size: PAES-4 uses four blocks, while PAES-8 uses eight blocks, targeting extra robustness in nonce-repeating scenarios.\"},{\"question\":\"What security analysis methods are included?\",\"answer\":\"The paper includes linear analysis and differential analysis, supported by AES properties such as the number of active S-boxes over several rounds.\"}]","PAES v1 - Parallelizable Authenticated Encryption Schemes based on AES Round Function | PDF",55]