On 09/16/2013 10:04 PM, Niels Möller wrote:
nisse@lysator.liu.se (Niels Möller) writes:
Nikos noted (off list) that Nettle's gcm hashing is slower than sha1. Which seems contrary to what's expected.
If people expect that gcm is faster than ha1, I'm curious how they reaon.
Hello Niels, It seems that also the original GCM description claims as such, although no details are given: http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/gcm/gcm-s...
There is also some talk that claims the same, but I couldn't access the (possibly more detailed) papers from the author, as they were behind a paywall. https://crypto.stanford.edu/RealWorldCrypto/slides/gueron.pdf%E2%80%8E
regards, Nikos