Re: Poly1305 vs. UMAC vs. new MAC1071
- From: "Tom St Denis" <tomstdenis@xxxxxxxxx>
- Date: 22 Nov 2006 03:43:49 -0800
D. J. Bernstein wrote:
<snip coolness>
I've started writing software for MAC1071, a new message-authentication
code that performs the above evaluation mod 2^107 - 1. I expect to end
up with cycle counts around half of the Poly1305-AES cycle counts on a
wide variety of CPUs, at the same comfortable >100-bit security level.
Coolness. So long as a the advantage for reasonable sized messages is
still less than 2^-40 or so for online attacks the MAC is still useful.
If you could accidentally provide some public domain portable code (asm
tweaks allowable provided they're not required) I may slip it in the
LTC frame work to benchmark it against the existing MACs I have (cmac,
pmac, xcbc, f9, hmac).
Tom
.
- Prev by Date: Re: Strongest encryption algorithm
- Next by Date: Re: Help required - Cryptography career
- Previous by thread: L15 prize increased to £100
- Next by thread: Re: Poly1305 vs. UMAC vs. new MAC1071
- Index(es):
Relevant Pages
|
|