F8
F8 mode (3GPP confidentiality mode) is a stream cipher mode designed for mobile telecommunications. It uses a block cipher with a salt key to derive a modified IV, then applies a counter-based keystream generation similar to CTR mode. The salt key prevents related-key attacks in multi-user environments. Used in UMTS and LTE networks for user data encryption.
Properties
| Property |
Value |
| Category |
Cipher Modes |
| Sub-category |
Stream Cipher Mode |
| Security status |
🛡️ Secure |
| Complexity |
Intermediate |
| Inventor |
3GPP Security Algorithms Group of Experts |
| Year |
2002 |
| Origin |
Not specified |
| Source |
algorithms/modes/f8.js |
Parameters
| Parameter |
Supported values |
| IV sizes |
8 bytes (64 bits) to 32 bytes (256 bits) in steps of 8 bytes |
| Salt key sizes |
4 bytes (32 bits) to 32 bytes (256 bits) |
Capabilities
| Flag |
Value |
RequiresIV |
Yes |
RequiresSaltKey |
Yes |
Security
Status: 🛡️ Secure
Known vulnerabilities
| Issue |
Description |
Mitigation |
| IV Reuse |
Reusing the same IV with the same key and salt reveals XOR of plaintexts. Always use unique IVs for each encryption session. |
— |
| Counter Overflow |
If block counter overflows during a session, keystream may repeat. Use appropriate message size limits. |
— |
| No Authentication |
F8 provides confidentiality only, not integrity or authentication. Combine with authentication mechanisms in practice. |
— |
Documentation
References
Test vectors
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — RFC 3711 B.1 AES-f8 (39 bytes, ‘pseudorandomness is the next best thing’)
| Field |
Value |
cipher |
AES |
key |
234829008467be186c3de14aae72d62c |
saltKey |
32f2870d |
iv |
006e5cba50681de55c621599d462564a |
input |
70736575646f72616e646f6d6e657373 20697320746865206e65787420626573 74207468696e67 |
expected |
019ce7a26e7854014a6366aa95d4eefd 1ad4172a14f9faf455b7f1d4b62bd08f 562c0eef7c4802 |
← All algorithms