Hawkynt

OCB

OCB (Offset CodeBook) is an authenticated encryption mode that provides both confidentiality and authenticity in a single pass. It uses offset-based processing that allows for parallel computation while maintaining strong security guarantees. OCB is highly efficient but was patent-encumbered until 2028.

Properties

Property Value
Category Cipher Modes
Sub-category Authenticated Encryption
Security status πŸ§ͺ Experimental
Complexity Research
Inventor Phillip Rogaway
Year 2001
Origin πŸ‡ΊπŸ‡Έ United States
Source algorithms/modes/ocb.js

Parameters

Parameter Supported values
IV sizes 12 bytes (96 bits) to 15 bytes (120 bits)

Capabilities

Flag Value
RequiresIV Yes

Security

Status: πŸ§ͺ Experimental

Known vulnerabilities

Issue Description Mitigation
Patent Status OCB was patent-encumbered until 2028, limiting adoption. Now free for use but still not widely deployed. β€”
Nonce Reuse Reusing nonces with the same key completely breaks OCB security and reveals plaintext patterns. β€”
Implementation Complexity OCB requires careful implementation of offset calculations and GF(2^128) arithmetic. β€”

Documentation

References

Test vectors

3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 β€” OCB round-trip test #1 - 1 byte

Field Value
key 000102030405060708090a0b0c0d0e0f
nonce bbaa99887766554433221100
aad (empty)
tagLength 16
input 01
expected (empty)

Vector 2 β€” OCB round-trip test #2 - 8-byte plaintext

Field Value
key 000102030405060708090a0b0c0d0e0f
nonce bbaa99887766554433221101
aad (empty)
tagLength 16
input 0001020304050607
expected (empty)

Vector 3 β€” OCB round-trip test #3 - With AAD

Field Value
key 000102030405060708090a0b0c0d0e0f
nonce bbaa99887766554433221102
aad 0001020304050607
tagLength 16
input 000102030405060708090a0b0c0d0e0f
expected (empty)

← All algorithms