+ o Change CTR mode description:
+
+ Truncated HASH from SKE (4 bytes) - This value is the first 4
+ bytes from the HASH value that was computed as a result of SKE
+ protocol. This acts as session identifier and each rekey MUST
+ produce a new HASH value.
+
+ to
+
+ Truncated HASH from SKE (4 bytes) - This value is the first 4
+ bytes from the HASH value that was computed in SKE. In each rekey
+ the value MUST be recomputed as follows:
+
+ HASH = hash(new Sending/Receiving IV from SKE)
+
+ The hash function is the one used in SKE. The 'new Sending/Receiving
+ IV from SKE' is the first 8 bytes of the new value computed during
+ rekey. The first 4 bytes are used from the recomputed HASH.
+