Re: dm-crypt, new IV and standards

From: dean gaudet
Date: Thu Mar 04 2004 - 20:20:26 EST


On Thu, 4 Mar 2004, Jean-Luc Cooke wrote:

> recommend using a MAC with CTR. (Why still have CTR? Unlike CBC, you can
> compute the N+1-th block without needing to know the output from the N-th
> block, so there is the possibility for very high parallelizum).

for disk crypto there are other opportunities for parallelism using
bitslicing to encrypt/decrypt multiple blocks in parallel (for example see
<http://www.cs.utexas.edu/users/atri/papers/spaa.ps>). there's a
latency/throughput tradeoff though...

-dean
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/