| ▲ | tptacek 2 hours ago | |||||||
Right, but balanced and unbalanced Feistel networks let you turn the 16-byte AES block into an arbitrarily small PRF. | ||||||||
| ▲ | cyberax 2 hours ago | parent [-] | |||||||
Well, yes. But at this point you're just making a new cipher with AES as the round function. And I think it should be at least as safe as the round function? I have not checked lately, but is it actually the recommendation for format-preserving encryption? | ||||||||
| ||||||||