Linux FSCRYPT development
 help / color / mirror / Atom feed
* Re: [PATCH v5 8/8] fscrypt: Add HCTR2 support for filename encryption
       [not found] ` <20220427003759.1115361-9-nhuck@google.com>
@ 2022-05-01 18:37   ` Eric Biggers
  0 siblings, 0 replies; only message in thread
From: Eric Biggers @ 2022-05-01 18:37 UTC (permalink / raw)
  To: Nathan Huckleberry
  Cc: linux-crypto, linux-fscrypt, Herbert Xu, David S. Miller,
	linux-arm-kernel, Paul Crowley, Sami Tolvanen, Ard Biesheuvel

On Wed, Apr 27, 2022 at 12:37:59AM +0000, Nathan Huckleberry wrote:
> HCTR2 is a tweakable, length-preserving encryption mode that is intended
> for use on CPUs with dedicated crypto instructions.  HCTR2 has the
> property that a bitflip in the plaintext changes the entire ciphertext.
> This property fixes a known weakness with filename encryption: when two
> filenames in the same directory share a prefix of >= 16 bytes, with
> AES-CTS-CBC their encrypted filenames share a common substring, leaking
> information.  HCTR2 does not have this problem.
> 
> More information on HCTR2 can be found here: "Length-preserving
> encryption with HCTR2": https://eprint.iacr.org/2021/1441.pdf
> 
> Signed-off-by: Nathan Huckleberry <nhuck@google.com>
> Reviewed-by: Ard Biesheuvel <ardb@kernel.org>

Acked-by: Eric Biggers <ebiggers@google.com>

- Eric

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2022-05-01 18:37 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <20220427003759.1115361-1-nhuck@google.com>
     [not found] ` <20220427003759.1115361-9-nhuck@google.com>
2022-05-01 18:37   ` [PATCH v5 8/8] fscrypt: Add HCTR2 support for filename encryption Eric Biggers

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox