FIPS 140-2 IG A.9 XTS key check.
[openssl.git] / CHANGES
diff --git a/CHANGES b/CHANGES
index abb03b4e4b30a8df4eca8e5d364adfd69988b427..d5ed4227cb397717267dd70f2e629cc0ff2fe760 100644 (file)
--- a/CHANGES
+++ b/CHANGES
   *) Add SM2 base algorithm support.
      [Jack Lloyd]
 
+  *) AES-XTS mode now enforces that its two keys are different to mitigate
+     the attacked described in "Efficient Instantiations of Tweakable
+     Blockciphers and Refinements to Modes OCB and PMAC" by Phillip Rogaway.
+     Details of this attack can be obtained from:
+     http://web.cs.ucdavis.edu/%7Erogaway/papers/offsets.pdf
+     [Paul Dale]
+
   *) s390x assembly pack: add (improved) hardware-support for the following
      cryptographic primitives: sha3, shake, aes-gcm, aes-ccm, aes-ctr, aes-ofb,
      aes-cfb/cfb8, aes-ecb.