30
A. Mileva et al.
Table 2.3 The current best FELICS results for scenario 1: Encrypt 128 bytes of data in CBC
mode
AVR
MSP
ARM
Code RAM Time
Code RAM Time
Code RAM Time
Cipher
(B)
(B)
(Cyc.)
(B)
(B)
(Cyc.)
(B)
(B)
(Cyc.)
FoM
Speck
966
294
39,875
556
288
31,360
492
308
15,427
5.1
Speck
874
302
44,895
572
296
32,333
444
308
16,505
5.2
Simon
1084
363
63,649
738
360
47,767
600
376
23,056
7.0
Simon
1122
375
66,613
760
372
49,829
560
392
23,930
7.2
RECTANGLE 1152 352
66,722
812
398
44,551
664
426
35,286
8.0
RECTANGLE 1118 353
64,813
826
404
44,885
660
432
36,121
8.0
LEA
1684
631
61, 020
1154
630
46,374
524
664
17,417
8.3
SPARX
1198
392
65,539
966
392
36,766
1200
424
40,887
8.8
SPARX
1736
753
83,663
1118
760
53,936
1122
788
67,581
13.2
HIGHT
1414
333
94,557
1238
328
120,716
1444
380
90,385
14.8
AES
3010
408
58,246
2684
408
86,506
3050
452
73,868
15.8
Fantomas
3520
227
141,838
2918
222
85,911
2916
268
94,921
17.8
Robin
2474
229
184,622
3170
238
76,588
3668
304
91,909
18.7
Robin
5076
271
157,205
3312
238
88,804
3860
304
103,973
20.7
RC5-20
3706
368
252,368
1240
378
386,026
624
376
36,473
20.8
PRIDE
1402
369
146,742
2566
212
242,784
2240
452
130,017
22.8
RoadRunneR
2504
330
144,071
3088
338
235,317
2788
418
119,537
23.3
RoadRunneR
2316
209
125,635
3218
218
222,032
2504
448
140,664
23.4
LBlock
2954
494
183,324
1632
324
263,778
2204
574
140,647
25.2
PRESENT
2160
448
245,232
1818
448
202,050
2116
470
274,463
32.8
PRINCE
2412
367
288,119
2028
236
386,781
1700
448
233,941
34.9
Piccolo
1992
314
407,269
1354
310
324,221
1596
406
294,478
38.4
TWINE
4236
646
297,265
3796
564
387,562
2456
474
255,450
40.0
LED
5156
574
2,221,555
7004
252
2,065,695
3696
654
594,453
138.6
2.2.2 Stream Ciphers
Stream ciphers encrypt small portions of data (one or several bits) at a time. By using
a secret key, they generate a pseudorandom keystream, which is then combined with
the plaintext bits to produce the ciphertext bits. Very often the combining function
is bitwise XORing, and in that case we speak about binary additive stream ciphers.
The basic security rule for stream ciphers is not to encrypt two different messages
with the same pair of key/IV. So, stream ciphers usually have a large keystream
period, and a different key and/or IV should be used after the period elapses. Each
stream cipher usually has an initialization phase with some number of rounds (or
clock-cycles), followed by an encryption phase. A fast initialization phase makes a
given cipher suitable for encrypting many short messages, while when several large
messages need to be encrypted, stream ciphers with a fast encryption phase are more
appropriate.
The standard stream cipher approach can be made lightweight by using: smaller
key sizes (e.g., 80 bits), smaller IV/nonce sizes (e.g., 64 bits), a smaller internal state
Précédent

- 44/268

Suivant