Mathematical #cryptography question. Suppose you wish to store a very large number (240 or more) of messages. All of these messages have the same relatively short length, on the order of 215 bits, and are to be encrypted with the same symmetric key.
In this regime, how do you size the IV and MAC for some target security level k? Still just k bits each, or does it get more interesting?