Thank you both Ondrej & Milan for the answers you provided. I'll wait for publication of Milan paper for further info. I read in linked conference material about lack of AE and integrity protection in linux filesystems. Meanwhile AE recently landed in linux port of ZFS filesystem [1][2]. It's currently based on AES-CCM/GCM. You probably know that already. I inform you just in case. [1] https://dqtpg127g2l9y.cloudfront.net/wp-content/uploads/2017/01/zfs-encryption-nov-2016.pdf [2] https://github.com/zfsonlinux/zfs Yours sincerely G. K. _______________________________________________ dm-crypt mailing list dm-crypt@xxxxxxxx http://www.saout.de/mailman/listinfo/dm-crypt