00837nas a2200193 4500000000100000000000100001008004100002653001100043653002900054653001700083653002300100100001800123700002000141700001700161245008200178300001000260490000700270520036600277 2017 d10aattack10aauthenticated encryption10ablock cypher10aleakage-resilience1 aFarzaneh Abed1 aFrancesco Berti1 aStefan Lucks00aAttacking a Leakage-Resilient Authenticated Encryption Scheme without Leakage a45-530 v373 a

Leakage-resilient authenticated encryption (AE) aims at privacy and authenticity against adversaries with an additional side channel. The first published “leakage resilient” AE scheme is the RCB block cipher mode. As it turns out, RCB is insecure, even if there is no side channel for the adversary. The current paper presents several attacks on RCB.