Announcement of Proposal to Update NIST SP 800-38E, Using the XTS-AES Mode for Confidentiality on Storage Devices

In August 2021, NIST's Crypto Publication Review Board announced the review of NIST Special Publication (SP) 800-38E, Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices. In response, NIST received public comments.

NIST proposes to update SP 800-38E to address the editorial suggestions in the public comments. In particular, the updated publication will mention the security vulnerability that results when the two AES (sub)keys are improperly generated to be identical, as discussed in Annex C.I of Implementation Guidance for FIPS 140-3 and the Cryptographic Module Validation Program.

The updated SP 800-38E would be published without a period of public comment.

Submit your comments on this decision proposal by March 10, 2023 to cryptopubreviewboard [at] (subject: Comments%20on%20Decision%20Proposal%20of%20SP%20800-106)  with "Comments on SP 800-38E Decision Proposal" in the subject line. Comments received in response to this request will be posted on the Crypto Publication Review Project site after the due date. Submitters’ names and affiliations (when provided) will be included, while contact information will be removed. See the project site for additional information about the review process.


SP 800-38E approves the XTS-AES technique by reference to its specification in IEEE Std. 1619-2007. The technique continues to serve the need for which i ..

Support the originator by clicking the read the rest link below.