Paper 2025/1888

HCTR2-FP and HCTR3-FP: Format-Preserving Encryption from Wide-Block Ciphers

Frank Denis, Fastly Inc.
Abstract

Format-preserving encryption (FPE) enables encryption while maintaining syntactic properties such as character sets. The current NIST standard FF1 uses multi-round Feistel networks that sacrifice performance for flexibility, while FF3-1 was withdrawn in 2025 following successful cryptanalytic attacks. FAST, proposed as a faster alternative, has not been widely implemented due to its complexity, leaving limited practical alternatives. We present HCTR2-FP and HCTR3-FP, format-preserving adaptations of the HCTR2 and HCTR3 wide-block tweakable ciphers. These variants preserve the single-pass Hash-Encrypt-Hash structure while operating on arbitrary radix domains through base-radix encoding and modular arithmetic. The constructions are simple to implement and analyze, and benchmarks demonstrate significant speedup over FF1.

Note: Added references to the Vistrutah and the Samvadini-AEAD papers.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
fpeformat preservingff1ff3ffxhctr2hctr3hctr2-fphctr3-fpencryption
Contact author(s)
fde @ 00f net
History
2025-11-19: revised
2025-10-09: received
See all versions
Short URL
https://ia.cr/2025/1888
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2025/1888,
      author = {Frank Denis},
      title = {{HCTR2}-{FP} and {HCTR3}-{FP}: Format-Preserving Encryption from Wide-Block Ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1888},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1888}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.