SHAKE Modes of Operation

October 3, 2023


Joan Daemen - Radboud University


Currently, the vast majority of symmetric-key cryptographic schemes are built as modes of block ciphers. What would cryptography look like if it was built around another primitive? In this presentation, we would like to explain our method to authentication, encryption and authenticated encryption (AE) using a standard sponge function like SHAKE128 or SHAKE256, or a reduced-round variant thereof, TurboSHAKE128 or TurboSHAKE256 [NIS15, BDH+23]

The Third NIST Workshop on Block Cipher Modes of Operation


