Comments on NIST’s RMAC Proposal
Phillip Rogaway · 2002
In standardizing a new mode of operation the first two goals are security and efficiency. Security should be demonstrated in the reduction-based provable-security paradigm: the belief that AES (say) is a good PRP should be enough to conclude that some MAC based on it is secure. This has become the generally-accepted way of demonstrating security. One might even say that a MAC design that fails to do at least this much fails to meet the accepted professional standard for the design of a new mode of operation. Efficiency is another central goal, and for an object as simple as RMAC this is rather easy to gauge. In terms of both demonstrated security and efficiency, NIST’s algorithm does not fare well. The remainder of this note assumes familiarity with the NIST draft and adopts the notations used there.