Thread (6 messages) 6 messages, 2 authors, 2012-09-25

Re: [PATCH 0/1] dm-integrity: integrity protection device-mapper target

From: Milan Broz <hidden>
Date: 2012-09-24 13:47:14
Also in: dm-devel, lkml

On 09/24/2012 11:55 AM, Dmitry Kasatkin wrote:
Both dm-verity and dm-crypt provide block level integrity protection.
This is not correct. dm-crypt is transparent block encryption target,
where always size of plaintext == size of ciphertext.

So it can provide confidentiality but it CANNOT provide integrity protection.

We need extra space to store auth tag which dmcrypt cannot provide currently.
dm-integrity provides a lighter weight read-write block level integrity
protection for file systems not requiring full disk encryption, but
which do require writability.
Obvious question: can be dm-verity extended to provide read-write integrity?

I would prefer to use standard mode like GCM to provide both encryption and
integrity protection than inventing something new.

Milan
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help