D UAL C OUNTER M ODE

Mike Boyle, C. J. Salter · 2001

INTRODUCTION For the past 18 months, the NSA has been developing a high-speed encryption mode for IP packets. The mode that we designed is identical in many aspects to Jutlas Integrity Aware Parallelizable Mode (IAPM). There is one important difference in our proposal. In the IP world, a large number of packets might arrive out of order. Integrity Aware Parallelizable Mode (IAPM) and the proposed variations incur a large overhead for out of order packets[JU 01]. Each packet requires at least the time to perform a full decryption to obtain an IV before decryption of the cipher can begin. This note describes our solution to this problem. First, we describe the basic mode and its features. We then describe how to implement this mode for IPSec. DUAL COUNTER MODE Dual counter mode is a hybrid of ECB mode and counter mode. Let E represent encryption by a codebook of width W. Let P 1, P 2 , ..., P j be j blocks of

Read the paper · More papers on PaperTik