On 14 Dec 2000, Nikita Borisov wrote:

> I think, though, that the "parallelization-friendliness" of the result
> is much more interesting than being able to encrypt and MAC at the same
> time.

Encrypt and MAC together are pretty useful too - it can result in a factor
of two improvement in speed on a single CPU system.

There's an improved version of the IBM mode at
http://csrc.nist.gov/encryption/aes/modes/ in the 'OCB mode' paper.

Clearly, it's a good idea to wait for new developments to stop happening
to use the new modes.

-Bram Cohen

"Markets can remain irrational longer than you can remain solvent"
                                        -- John Maynard Keynes


Reply via email to