3 ms·
It's in the Wikipedia entry, even. https://en.wikipedia.org/wiki/Galois/Counter_Mode https://en.wikipedia.org/wiki/Galois/Counter_Mode GCM = CTR + GMAC If you
by CiPHPerCoder 9y ago
It's in the Wikipedia entry, even. https://en.wikipedia.org/wiki/Galois/Counter_Mode https://en.wikipedia.org/wiki/Galois/Counter_Mode
GCM = CTR + GMAC
If you're, elsewhere, using GMAC for some reason and getting a different result when you combine it with CTR mode: Well, that's weird. I'd have to have two implementations to compare to analyze further. But otherwise, this conversation is moot.
- klodolph 9y agoIf you look at the block diagram in the GCM article you linked, you'll see that the second-to-last block of data added to the authentication tag is len(A)||len(C). These are 64-bit values, concatenated to form a single 128-bit value. So if you use GMAC, you'll have len(A) >= 0, and len(C) == 0. If you use GCM with encrypted data, you'll end up with len(C) > 0, which will give you different results from GMAC. GMAC is a special case of GCM, and GCM is not simply GMAC + CTR. This is supported by the NIST publication which defines them: > If the GCM input is restricted to data that is not to be encrypted, the resulting specialization of GCM, called GMAC, is simply an authentication mode on the input data. Again, GCM != CTR + GMAC, if you make this assumption you will fail to interoperate with correct implementations of GCM.
- tptacek 9y agoThis is silly. You can call CTR + HMAC-SHA2 an AEAD (if you make allowances for extra data), and it will be one. But if you give two people the independent task to generate a CTR+HMAC-SHA2 AEAD construction, their results will not interoperate (which you might or might not care about). You're fixated on the fact that GCM is at pains to make sure it interoperates, and so specifies specific details about how to couple AES-CTR and GHASH. Every AEAD construction has to do that. That doesn't mean they're not compositions of ciphers and MACs.