You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, GKWY19 (https://eprint.iacr.org/2019/ ) says that half-gates hash function can be instantiated with ccr instead of tccr.
Does that mean that when instantiating half-gates' H with ccr, tweak re-use becomes a non-issue and the miTCCR hash instantiation is no longer needed?
The text was updated successfully, but these errors were encountered:
Do note that miTCCR is proposed in a paper AFTER GKWY19 (thus GKWY19 cannot say anything about a future construction) and note that ccr, tccr and mitccr are all different. Using TCCR lead to a secure GC in the most straightforward manner; GKWY19 shows that CCR can be used and provably secure when used in the way we described in the paper; miTCCR provides better concrete security in this context.
Hi, GKWY19 (https://eprint.iacr.org/2019/ ) says that half-gates hash function can be instantiated with ccr instead of tccr.
Does that mean that when instantiating half-gates' H with ccr, tweak re-use becomes a non-issue and the miTCCR hash instantiation is no longer needed?
The text was updated successfully, but these errors were encountered: