OCB
OCB (Offset CodeBook) is an authenticated encryption mode that provides both confidentiality and authenticity in a single pass. It uses offset-based processing that allows for parallel computation while maintaining strong security guarantees. OCB is highly efficient but was patent-encumbered until 2028.
Properties
| Property |
Value |
| Category |
Cipher Modes |
| Sub-category |
Authenticated Encryption |
| Security status |
π§ͺ Experimental |
| Complexity |
Research |
| Inventor |
Phillip Rogaway |
| Year |
2001 |
| Origin |
πΊπΈ United States |
| Source |
algorithms/modes/ocb.js |
Parameters
| Parameter |
Supported values |
| IV sizes |
12 bytes (96 bits) to 15 bytes (120 bits) |
Capabilities
| Flag |
Value |
RequiresIV |
Yes |
Security
Status: π§ͺ Experimental
Known vulnerabilities
| Issue |
Description |
Mitigation |
| Patent Status |
OCB was patent-encumbered until 2028, limiting adoption. Now free for use but still not widely deployed. |
β |
| Nonce Reuse |
Reusing nonces with the same key completely breaks OCB security and reveals plaintext patterns. |
β |
| Implementation Complexity |
OCB requires careful implementation of offset calculations and GF(2^128) arithmetic. |
β |
Documentation
References
Test vectors
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β OCB round-trip test #1 - 1 byte
| Field |
Value |
key |
000102030405060708090a0b0c0d0e0f |
nonce |
bbaa99887766554433221100 |
aad |
(empty) |
tagLength |
16 |
input |
01 |
expected |
(empty) |
Vector 2 β OCB round-trip test #2 - 8-byte plaintext
| Field |
Value |
key |
000102030405060708090a0b0c0d0e0f |
nonce |
bbaa99887766554433221101 |
aad |
(empty) |
tagLength |
16 |
input |
0001020304050607 |
expected |
(empty) |
Vector 3 β OCB round-trip test #3 - With AAD
| Field |
Value |
key |
000102030405060708090a0b0c0d0e0f |
nonce |
bbaa99887766554433221102 |
aad |
0001020304050607 |
tagLength |
16 |
input |
000102030405060708090a0b0c0d0e0f |
expected |
(empty) |
β All algorithms