International Association for Cryptologic Research
In this paper, the authors provide a security analysis for full-state keyed Sponge and full-state Duplex constructions. Their results can be used for making a large class of Sponge-based authenticated encryption schemes more efficient by concurrent absorption of associated data and message blocks. In particular, they introduce and analyze a new variant of Sponge Wrap with almost free authentication of associated data. The idea of using full-state message absorption for higher efficiency was first made explicit in the Donkey Sponge MAC construction, but without any formal security proof.