RE: XCB-32-AES for wide-block encryption
Shai Halevi wrote:
> Jim.Williams@Emulex.Com wrote:
>
> > Shai Halevi wrote:
> >
> >>the mode of Jim Williams (Jim, do you have a name for it?)
> > Perhaps MNR (modified naor-reingold) would be appropriate.
> Why modified? From the very brief look that I took, the only difference
> that I saw was the inclusion of the tweak. Is there anything else?
I believe that the original N-R paper included one additional
hash denoted as U1 (the 1 begin subscript). In the proposed
implementation, this appears unnecessary. Please correct me
if I am wrong on either count.
Thanks, Jim