[Cryptography] Best way to create a MAC from SHA3

Phillip Hallam-Baker phill at hallambaker.com
Fri Feb 22 15:10:24 EST 2019


I am just finishing off the UDF draft.

What is the best way to create a MAC from a SHA3 digest function? For this
application I need a 512 bit output so no need to SHAKE.

HMAC is an obvious choice but it was designed to overcome the limitations
of Merkle Damgard construction. Is there a more appropriate, spongeworthy
choice?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20190222/8c0596b6/attachment.html>


More information about the cryptography mailing list