EME (ECB-Mask-ECB) is a wide-block tweakable cipher mode that can handle variable-length inputs while preserving format. It uses a three-round construction: ECB encrypt, mask with universal hash, then ECB encrypt again. Primarily used for format-preserving encryption applications.
| Property | Value |
|---|---|
| Category | Cipher Modes |
| Sub-category | Wide-Block Tweakable Mode |
| Security status | π§ͺ Experimental |
| Complexity | Research |
| Inventor | Shai Halevi, Phillip Rogaway |
| Year | 2003 |
| Origin | πΊπΈ United States |
| Source | algorithms/modes/eme.js |
| Flag | Value |
|---|---|
RequiresIV |
No |
Status: π§ͺ Experimental
| Issue | Description | Mitigation |
|---|---|---|
| Research Status | EME mode is primarily used in specialized format-preserving encryption applications and has limited real-world deployment. | β |
| Implementation Complexity | Requires careful implementation of universal hash functions and proper masking operations. | β |
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β EME round-trip test - single block
| Field | Value |
|---|---|
key |
2b7e151628aed2a6abf7158809cf4f3c |
tweak |
000102030405060708090a0b0c0d0e0f |
input |
6bc1bee22e409f96e93d7e117393172a |
expected |
(empty) |