Block Cipher Modes
Niels Ferguson, Bruce Schneier, Tadayoshi Kohno · 2015
If we want to encrypt something that is not exactly one block long, we have to use a block cipher mode. There are many ways to pad the plaintext, but the most important rule is that the padding must be reversible. The cipher block chaining (CBC) mode is one of the most widely used block cipher modes. The IV necessary for CBC encryption is generated by encrypting the nonce. Counter mode, generally known by the three-letter abbreviation CTR, is another block cipher encryption mode. This chapter discusses several modes, but there are really only two modes we would consider using: CBC and CTR. Then, the chapter highlights that all block cipher modes leak some information. If a collision occurs in CBC mode, there will be a leak of 128 bits of information about the plaintext. It is a good policy to keep the probability of such a collision low.