User Tools

Site Tools


ae

This is an old revision of the document!


Table of Contents

++AE

The Algorithm

  • Author(s): Francisco Recacha
  • CAESAR submission: ++AE

Cryptanalysis

Damien Vizár pointed out in this thread a trivial forgery attack for input where the last block of associated data is not a multiple of the block length. This is due to the padding rule for the last associated data block: rather than using 10* padding, padding is done using only zeroes. This can be fixed using 10* padding instead.

ae.1395390961.txt.gz · Last modified: 21/03/2014 08:36:01 by mmeh