On Thu, Jan 4, 2018 at 2:02 PM, Niels Möller nisse@lysator.liu.se wrote:
What about OCB (for which RFC 7253 may be the most appropriate spec)? As far as I'm aware, it's one of few AEAD modes which provides a significant performance advantage over doing MAC and encryption separately.
(I'll need some time to check about the other questions)
I'd stay away from OCB. libgcrypt had to amend their license for that: https://github.com/gpg/libgcrypt/blob/master/LICENSES
regards, Nikos