comparing RMAC to AES+CBC-MAC or XCBC (Re: Why is RMAC resistant to birthday attacks?)

Jack Lloyd lloyd at
Wed Oct 23 12:37:47 EDT 2002

On Tue, 22 Oct 2002, Adam Back wrote:

> The one difference which is an incremental improvement over raw
> CBC-MAC is that the final CBC-MAC a-like output is encrypted with the
> 2nd key K3.  (K3 defined as K2 xor salt, K2 an independent key).

Which isn't even a new idea (it's done in ANSI X9.19, for example).

