24
A. Mileva et al.
• Add-Rotate-XOR (ARX)—only three operations are used: modular addition,
rotation and XOR.
• Generalized Feistel Network (GFN)—divides the input block into n parts, and
each round consists of a round-function layer and a block-permutation layer,
which usually is a cyclic shift. If the round-function is applied only to one part,
we speak about Type-1, and if it is applied on the n/2 parts, we speak about
Type-2 GFN. If there is an additional linear layer between the two layers, we
speak about Extended GFN [78].
• LFSR-based—in the round function they use one or more Linear Feedback Shift
Registers (LFSRs) in combination with non-linear functions.
• LS-design—each round combines linear diffusion L-boxes with non-linear
bitslice S-boxes, and they are aimed at efficient masked implementations against
side-channel analysis [247].
• XLS-design—a variation of the LS-design, that uses the additional ShiftColumns
operation, and Super S-boxes [306].
There are also tweakable block ciphers, which in addition to the key and the
message have a third input named tweak, and they must be secure even if the attacker
is able to control the tweak input. Each tweakable block cipher can be seen as a
family of permutations in which each (key, tweak) pair selects one permutation.
The standard block cipher approach can be made lightweight by using smaller
key sizes (e.g., 80 or 96 bits), smaller block sizes (e.g., 64 bits), smaller or
special building blocks (e.g., 4-bit S-boxes, no S-boxes at all, or recursive diffusion
layers), simpler key schedules (e.g., selecting a key schedule where bits from the
master key are selected as round keys), smaller hardware implementation, involutive
encryption, etc. AES-128 belongs in this group also, because there are ASIC
implementations of it with an area of just 2400 GE[426] on 0.18 µm technology, but
it cannot be applied in every scenario. In Table 2.1, we give a summary of the known
lightweight block ciphers, sorted in alphabetical order, with their type, key and block
size in bits, number of rounds, used technology and number of GEs if known, and we
give the best known attacks in Table 2.2. KASUMI used in UMTS, GSM, and GPRS
mobile communications systems, 3-Way and MANTIS are considered insecure.
Additionally, CLEFIA and PRESENT are part of the ISO-29192-2 standard, while
HIGHT, MISTY1 and AES are part of the ISO/IEC 18033-3:2010 standard.
For fair and consistent evaluation and comparison of software implementations
of lightweight block and stream ciphers, one can use a free and open-source
benchmarking framework FELICS (Fair Evaluation of Lightweight Cryptographic
Systems) [182]. Currently, the assessment can be done on three widely used
microcontrollers: 8-bit AVR, 16-bit MSP and 32-bit ARM, and extracted metrics
are the execution time, RAM consumption and binary code size, from which one
single value “Figure Of Merit” (FOM) is calculated. Table 2.3 presents some details
about software performance of some lightweight block ciphers with the current
best FELICS results for encryption of 128 bytes of data in CBC mode (scenario
1 in [182]), sorted according to the FoM measure, where the lowest result is the
best.
Précédent

- 38/268

Suivant