2 Catalog and Illustrative Examples of Lightweight Cryptographic Primitives
23
The main objective of this chapter is to offer to practitioners, researchers and
all interested parties a short categorized catalog of existing symmetric lightweight
primitives with their main features, some details about known software and
hardware performance, and existing security analysis, to enable selection according
to specific needs. These cryptographic primitives can be categorized into five
areas: block and stream ciphers, hash functions, message authentication codes,
and authenticated encryption schemes. As a consequence of the simplicity which
provides lightweightness, the security evaluation of lightweight stream ciphers
appears as an issue of top importance, and so a number of illustrative elements
relevant for cryptanalysis of lightweight encryption techniques have been pointed
out as well.
It can easily be observed that (see Sect. 2.2) almost all of the recently designed
lightweight ciphers are block ciphers. The requirement for unnecessarily large
internal states results in extra hardware area cost which definitely hinders designing
ultralightweight stream ciphers. We analyze the arguments behind this criterion
and propose to loosen it by justifying the security analysis in Sect. 2.3. We believe
this adoption will promote the design and even the analysis of lightweight stream
ciphers.
2.2 Catalog of Lightweight Cryptographic Primitives
The catalog of lightweight cryptographic primitives is divided in five categories:
block and stream ciphers, hash functions, message authentication codes, and
authenticated encryption schemes.
2.2.1 Block Ciphers
Block ciphers encrypt one block of plaintext bits at a time, to a block of ciphertext
bits, through multiple rounds, and using a secret key. Each round is a sequence
of several simple transformations, which provide confusion and diffusion [522].
In each round, a round key is used, which is derived from the secret key using a
key schedule algorithm. According to the algorithm structure, block ciphers can be
divided into several types:
• Substitution Permutation Network (SPN)—each round consists of substitution
(S-) and permutation (P-) boxes. Usually, S-boxes are non-linear transformations
and provide confusion, while P-boxes are linear and provide diffusion.
• Feistel Network (Feistel)—divides the input block into two halves, L i and R i ,
and in each round, the output block is (L i+1 , R i+1 ) = (R i , L i ⊕ F (R i , K i+1 )),
where F is the round-function (introduced by H. Feistel [209]).
Précédent

- 37/268

Suivant