A Note on NSA's Dual Counter Mode of Encryption

Pompiliu Donescu, Virgil D. Gligor, David A. Wagner · 2001

. We show that both variants of the Dual Counter Mode of encryption (DCM) submitted for consideration as an AES mode of operation to NIST by M. Boyle and C. Salter of the NSA are insecure with respect to both secrecy and integrity in the face of chosen-plaintext attacks. We argue that DCM cannot be easily changed to satisfy its stated performance goal and be secure. Hence repairing DCM does not appear worthwhile. 1

Read the paper · More papers on PaperTik