A Characterization of Authenticated-Encryption as a Form of Chosen-Ciphertext Security

In this note we introduce a variation of the standard definition of chosen-ciphertext security, which we call IND-CCA3, and prove that IND-CCA3 is equivalent to authenticated-encryption.