Wait, AES with a minimum of 256 bits? Might be a typo, but there's only one AEAD AES with no more than 256-bits right? Is there key whitening? (I find it odd that few algorithms have strong or independently generated whitening keys, particularly given that one of the arguments for 128-bit DES is that it would only have 20% more gates)