2

Is SIV mode variant equally secure, if you replace CTR mode encryption with full-block CFB mode encryption?

CFB seems to be safe with predictable IV: Is using a predictable IV with CFB mode safe or not?

But is it safe with Encrypt-and-MAC like construction as SIV?

LightBit
  • 1,741
  • 14
  • 28

1 Answers1

0

I have found this IETF expired draft.

It says:

E must be a length-preserving semantically-secure encryption scheme.

Also considering comments. I believe CFB or OFB can also be used in SIV.

ECB or CBC (without ciphertext stealing) would not be secure, because of padding which can cause errors while decrypting (not length-preserving).

LightBit
  • 1,741
  • 14
  • 28