From: Sergey Matveev Date: Mon, 21 Apr 2025 15:41:40 +0000 (+0300) Subject: Note about MACs ordering X-Git-Url: http://www.git.cypherpunks.su/?a=commitdiff_plain;h=5826d7f231c60a65c62d456b1f1e5190b4c56a597240dbfc55a1bfd498e68c9f;p=keks.git Note about MACs ordering --- diff --git a/spec/cm/dem-xchapoly-krmr.texi b/spec/cm/dem-xchapoly-krmr.texi index 989a5d3..f812648 100644 --- a/spec/cm/dem-xchapoly-krmr.texi +++ b/spec/cm/dem-xchapoly-krmr.texi @@ -27,6 +27,8 @@ randomised 192-bit nonce (initialisation vector) are derived from it. Nonce's lowest bit is set only if this is the last chunk we encrypting. +MACs are ordered the same way as KEMs in the list. + @code{/payload}'s chunk length equals to 128KiB+16+32*recipients bytes. HKDF is KDF algorithm,