3 ms·
Depends how your stream encryption is done and what you mean by stream encryption. - If you mean encryption of messages using a stream cipher, generally a sing
by problems 9y ago
Depends how your stream encryption is done and what you mean by stream encryption.
- If you mean encryption of messages using a stream cipher, generally a single IV is used per message so it could be used there.
- If you mean encryption of a stream of data, well, if you're using a block cipher to encrypt a stream of data, this indeed could be used as a block cipher inherently creates blocks in the data every X bits.
- However, if you're encrypting a stream of data using a stream cipher it is indeed impossible as all data in the stream isn't known when encryption begins.
- kobeya 9y agoI mean encryption of data as it is generated, in a single pass. This entire message is not known, so unless I am misunderstanding, it is not possible to do per-message deterministic nonce generation.
- dom0 9y agoGenerally speaking, streaming AEAD is discouraged on an API level, because it incentivises using unauthenticated intermediate decryption results. Thus, block the data into reasonably sized blocks. Also, yes.
- dchest 9y agoThe author of the linked blog post has a post exactly about this: https://www.imperialviolet.org/2014/06/27/streamingencryption.html https://www.imperialviolet.org/2014/06/27/streamingencryptio... (I defined and implemented a variant of Adam's idea with NaCl secretboxes: https://github.com/dchest/nacl-stream-js https://github.com/dchest/nacl-stream-js)