3 research outputs found
Error Oracle Attacks on CBC Mode: Is There a Future for CBC Mode Encryption?
This paper is primarily concerned with the CBC block cipher mode.
The impact on the usability of this mode of recently proposed
padding oracle attacks, together with other related attacks
described in this paper, is considered. For applications where
unauthenticated encryption is required, the use of CBC mode is
compared with its major symmetric rival, namely the stream cipher.
It is argued that, where possible, authenticated encryption should
be used, and, where this is not possible, a stream cipher would
appear to be a superior choice. This raises a major question mark
over the future use of CBC mode, except as part of a more complex
mode designed to provide authenticated encryption