logoalt Hacker News

tptacekyesterday at 11:37 PM1 replyview on HN

Right, but balanced and unbalanced Feistel networks let you turn the 16-byte AES block into an arbitrarily small PRF.


Replies

cyberaxyesterday at 11:42 PM

Well, yes. But at this point you're just making a new cipher with AES as the round function. And I think it should be at least as safe as the round function?

I have not checked lately, but is it actually the recommendation for format-preserving encryption?

show 1 reply