NIST has released a draft revision of Special Publication (SP) 800-38E, which approves the XTS-AES mode of operation for protecting the confidentiality of data on storage devices. Revision 1 updates the referenced specification to IEEE Std. 1619-2025 and
NIST has released a draft revision of Special Publication (SP) 800-38E, Recommendation for Block Cipher Modes of Operation: XTS-AES Mode for Confidentiality on Storage Devices, which approves the XTS-AES mode of operation for protecting the confidentiality of data on storage devices. Revision 1 updates the referenced specification to IEEE Std. 1619-2025 and clarifies NIST’s requirements for the approved use of XTS-AES, including its scope of use, data-unit and key-scope limits, key requirements, and the ordering convention for ciphertext stealing.
Rather than reproducing the XTS-AES specification, this recommendation incorporates IEEE Std. 1619-2025 by reference. To facilitate review of the draft revision, IEEE Std. 1619-2025 is publicly available during the public comment period.
The public comment period is open through October 16, 2026. See the publication details for additional information, including the draft SP and a link to the IEEE standard.
NOTE: A call for patent claims is included in this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.