It makes NORX more robust, e.g., it protects against forgery / key-recovery attacks, see slide 15 of https://www.nuee.nagoya-u.ac.jp/labs/tiwata/fse2017/slides/07-01.pdf … /cc @sevenps
-
-
-
In NMR NORX, why doesn’t AEADEnc return (C, T, T’) so that AEADDec would require a single pass?
- 10 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.