Is miTCCR still needed in light of GKWY19 findings?
themighty1 opened this issue · 3 comments
Hi, GKWY19 (https://eprint.iacr.org/2019/ ) says that half-gates hash function can be instantiated with ccr instead of tccr.
Does that mean that when instantiating half-gates' H with ccr, tweak re-use becomes a non-issue and the miTCCR hash instantiation is no longer needed?
Hey, @wangxiao1254, I would be thankful if you could share your opinion on this matter.
Hi, @wangxiao1254 , could you pls shed some light on this? Thanks.
Do note that miTCCR is proposed in a paper AFTER GKWY19 (thus GKWY19 cannot say anything about a future construction) and note that ccr, tccr and mitccr are all different. Using TCCR lead to a secure GC in the most straightforward manner; GKWY19 shows that CCR can be used and provably secure when used in the way we described in the paper; miTCCR provides better concrete security in this context.