1

The Wikipedia article on GCM says GCM can take full advantage of parallel processing.

I had thought GCM uses a random IV for the first block, then for the second block uses the results of encrypting the previous block as the IV. If this is correct, how can it possibly be done in parallel?

The question boils down to which of these statements is wrong, and why?

kmort
  • 165
  • 6
  • Does [this answer](https://crypto.stackexchange.com/a/27468/23623) answer your question? – SEJPM Sep 12 '18 at 18:45
  • @SEJPM Yeah. Same question.... I'm deleting mine. Thanks! – kmort Sep 12 '18 at 18:47
  • No, please don't delete. I'll mark it as a duplicate so others who can find your wording easier (using a search machine) will be redirected! – SEJPM Sep 12 '18 at 18:49

0 Answers0