[Cryptography] [Crypto-practicum] Justify the sequence of operations in CTR mode.

Ryan Carboni ryacko at gmail.com
Tue Feb 16 14:03:59 EST 2016


Why not use single-key Even-Mansour-like construction?

Ciphertext = E( E(CTR) XOR plaintext)) XOR E(CTR)

Costs only two encryptions, both parallelizable, and has the security of at
least Even-Mansour with a single key, single plaintext-ciphertext pair. At
which point the easiest route is to attack the kernel, not an oracle attack.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20160216/faf27bda/attachment.html>


More information about the cryptography mailing list