Re: Authenticating encrypted messages?

From: Mok-Kong Shen (mok-kong.shen_at_t-online.de)
Date: 11/30/04


Date: Tue, 30 Nov 2004 11:59:55 +0100


Mok-Kong Shen wrote:
>
[snip]
> Xw{j+1} := F( G(Xwj,Pwj), Cw{j+1} )
>
> (The locations for obtaining the rotation amounts may, of
> course, be different for F and G.)

While mutual rotations would imply more 'complexity' for
the opponent, the processing cost is of course also higher
than doing rotation of only one operand in the combination
employing either modular addition or XOR, which may be
considered as 'special' case of F or G. (There are people
very sensitive to the figure of cycles per byte.) I tend
to think that the earlier proposal or its variant, namely
doing two separate steps akin to the equation above (but
using one rotation), could already be sufficient for our
purpose.

M. K. Shen


Quantcast