> There are two ways that I see to solve the IV collision issue: > > 1. Allow longer IVs: The GCM spec allows IVs of any size, we can just > do the same for 1619.1, and leave it to the application to > decide how > to set the IV and to what size. The application can then > set the IV to > include the vendor-ID and whatever else it wants to put there. (Does > the CCM spec allow long IVs?) just allow any-size IV and put some appendix that > describe the multi-vendor IV issue and sketches the two > solutions above.
I strongly favor this option. chongo (*) /\oo/\