Re: AES MAC security question

From: Mike Amling (nospam_at_nospam.com)
Date: 07/04/05


Date: Sun, 03 Jul 2005 22:20:16 GMT

Rein Anders Apeland wrote:
>
> Now, that were some ideas I liked, thank you! Limit processing to
> e.g. one packet per second and having a shared secret included in
> the MAC too.

   The MAC key is already a shared secret, no?

> Actually I have though of adding a second layer of encryption,
> where the whole packet (MAC, ID, counter and cmd) is encrypted with
> a shared (between one car and its fobs) key before transmission.
> However, this lies uncomfortably close to the Microchip KEELOQ
> patent. :D
>
> What would be the difference, from a safety point-of-view, between
> including a shared secret in the MAC and my suggestion for a second
> layer of encryption?

--Mike Amling