
基于双重分组和密钥计数的并行认证模式
黄玉划、胡爱群、宋宇波
Parallel Authentication Modes Based on Double Blocks or Key Counter
Huang Yuhua、 Huai Aiqun、 Song Yubo
由于CBC-MAC模式不可并行处理,提出了一种基于双重分组的并行认证模式(PKCB)。PKCB模式同并行认证模式PMAC相比,安全性和速率都有显著提高,PKCB认证模式与CTR(计数器)加密模式结合可构成分组密码算法的一种全工作模式。在此基础上提出了一种基于密钥计数的并行认证模式(KCTR-MAC)。KCTR-MAC模式安全性比PMAC模式高得多,而速率未降低,KCTR-MAC认证模式和CTR加密模式结合也可构成分组密码算法的一种全工作模式(2CTR),2CTR模式的综合性能不亚于标准模式CCM(CTR with CBC-MAC),是一种安全快速的实用模式。
The CBC - MAC mode is not a parallel one. A parallel authentication mode (PKCB) based on double blocks was put forward in this paper. The PKCB mode had a marked improvement on security & speed over parallel authentication mode, PMAC. And it may be combined with the CTR (counter) encryption mode to form a full block cipher mode. On this ground, another parallel authentication mode (KCTR - MAC) based on key counter was advanced. As compared with the PMAC mode, the KCTR - MAC mode had a marked improvement on security, while its speed did not become lower. The KCTR - MAC authentication mode may be combined with the CTR (counter) encryption mode to form a full block cipher mode (2CTR),too. The 2CTR mode had a performance advantage over the standard mode, CCM (CTR with CBC - MAC). And it was a fast, practicable mode with security.
认证模式 / CBC-MAC模式 / PMAC模式 / CTR模式 / CCM模式
authentication mode / CBC - MAC mode / PMAC mode / CTR mode / CCM mode
/
〈 |
|
〉 |