3 ms·
I consider that a feature, considering that cipher is AES. In fact, I would consider the AES-192 support superfluous. I wonder why they chose to support CCM in
by briansmith 16y ago
I consider that a feature, considering that cipher is AES. In fact, I would consider the AES-192 support superfluous.
I wonder why they chose to support CCM instead of GCM.
- tptacek 16y agoBecause CCM is better documented and more popular than GCM, despite its (minor) flaws. If they wanted to look cool, they should have done EAX mode. Help me understand why people always make a point of sticking up for GCM. I've read the paper and I don't get what's so great about it. (For everyone else: ECB means "you can can cut-and-paste-and-shuffle blocks in the ciphertext", CBC means "you can't", CFB, OFB, and CTR mean "you can encrypt one byte at a time", and CCM, GCM, OCB, and EAX mean "you can encrypt one byte at a time and authenticate the message automatically so that it can't be tampered with".)
- briansmith 16y agoAES-GCM is in NSA Suite B and AES-CCM and AES-EAX aren't. IIRC, EAX isn't even NIST approved. GCM is parallelizable, and CCM and EAX aren't. New Intel processors have special support for GCM, which should makes GCM notably faster. http://www.cryptopp.com/wiki/EAX_Mode http://www.cryptopp.com/wiki/EAX_Mode has a very brief but good summary of the advantages of GCM over CCM and EAX. Also see this slide (warning: PPT): http://www.cryptopp.com/w/images/c/ce/AtE-Comparison.ppt http://www.cryptopp.com/w/images/c/ce/AtE-Comparison.ppt
- tptacek 16y agoAnd there's my answer. Thanks!