|
|
|
|
|
by Retr0id
717 days ago
|
|
My natural follow-up question was "why can't you just have K1 = L?" Obviously it's inherited from CMAC, but why does CMAC do it? Investigating further, general-case CMAC involves generating a K1 and a K2, which afaict just need to be arbitrarily different from each other. So why not something even simpler, like "xor with 1"? |
|
The input here is highly restricted so there's no point to it.