2 @section Cipher modes of operation
4 @ref{en2814789, GOST 28147-89} standard defines the following modes of
5 operation for Magma cipher:
15 @item 28147-89 MAC is completely unusable:
17 @item Reduced 16-round Magma cipher is used instead of 32 one.
18 @item Authenticating data does not have neither padding, nor
19 length specifying, so @code{MAC(0xDEAD) = MAC(0xDEAD00)}.
21 @item Specified counter (CTR) mode increments counters with predefined
22 constants for 32-bit halves of the block. This differs from simpler
23 counter mode implementations.
26 Modern @strong{GOST R 34.13-2015} standard defines the following modes
39 @item Common simple counter mode implementation.
40 @item Specified MAC is identical to
41 @url{https://en.wikipedia.org/wiki/CMAC, CMAC} and can be used safely.