Is authentication needed for field encryption?
EDIT: I should add that is for fields with unique values. So, constant key & IV (per column), but unique data for each field.
Is authentication needed for field encryption?
EDIT: I should add that is for fields with unique values. So, constant key & IV (per column), but unique data for each field.
Depends on what kinds of data you're encrypting but if its anything to do with money or health data authenticity is a must.
But how can attacker control what plaintext will become, if he doesn't have a key? Wouldn't he be limited to either a random value or a value from another field?
Since IV is constant. It doesn't need to be stored in DB and can be treated like a key. So, attacker (with an access to DB) can't change IV for a server app reading from the DB.
How do the following methods compare when using constant IV?
AES-CBC + HMAC (encrypt then MAC) vs AES-GCM-SIV vs AES-SIV
(The linked article talks about CTR + HMAC, but CBC + HMAC is also affected.)