On 03/27/2013 06:56 PM, Niels Möller wrote:
In any case if you consider that limitation, a stopper, I could check it further.
To get to understand the algorithm better, I'm writing a toy implementation. I'll let you know when I have a poly128-routine which passes the tests.
Note also that I realized that in the implementation I submitted the nonce is restricted to 64-bits, while up to 128-bits may also be used.
regards, Nikos