Grain-128AEAD, Round 3 Tweak and Motivation
Weaknesses in the Grain-128AEAD key re-introduction, as part of thecipher initialization, are analyzed and discussed. We consider and analyzeseveral possible alternatives for key re-introduction and identify weaknesses, or potential weaknesses, in them. Our results show that it seemsfavorable to separate the state initialization, the key re-introduction, andthe A/R register initialization into thr
