2 Catalog and Illustrative Examples of Lightweight Cryptographic Primitives
31
(e.g., 80 or 100 bits), simpler key schedules, a smaller hardware implementation,
etc. Table 2.4 lists the known lightweight stream ciphers in alphabetical order, with
their main parameters and details about hardware implementation, and Table 2.5
provides the best known attacks. One can notice that all eSTREAM Profile 2
candidates that were not selected as finalists are not in the table. Also, according
to the hardware implementations, ZUC, ChaCha and Salsa20 cannot really be
considered as lightweight. While Lizard uses 120 bit keys, its designers claim only
80-bit security against key-recovery attacks. A5/1 used in GSM protocol, E0 used
in Bluetooth, A2U2, and Sprout are considered insecure.
Additionally, Enocoro and Trivium are part of the ISO/IEC 29192-3:2012
standard, and Rabbit is part of ISO/IEC 18033-4:2011. SNOW 3G was chosen
for the 3GPP encryption algorithms UEA2 and UIA2, while ZUC was chosen for
the 3GPP algorithms 128-EEA3 and 128-EIA3. The profile 2 eSTREAM portfolio
includes Grain v1, MICKEY 2.0 and Trivium. There is an IETF implementation of
the ChaCha20, published in RFC 7539, with 96-bit nonce and maximum message
length up to 2 32 − 1B that can be safely encrypted with the same key/nonce, as a
modification.
2.2.3 Hash Functions
A hash function is any function that maps a variable length input message into a
fixed length output. The output is usually called a hashcode, message digest, hash
value or hash result. Cryptographic hash functions must be preimage (one-way),
second preimage and collision resistant.
Usually the message is first padded and then divided into blocks of fixed length.
The most common method is to iterate over a so-called compression function, that
takes two fixed size inputs, a message block and a chaining value, and produces
the next chaining value. This is known as a Merkle-Damgård (MD) construction.
The sponge construction is based on fixed-length unkeyed permutation (P-Sponge)
or random function (T-Sponge), that operates on b bits, where b = r + c. b is
called the width, r is called the rate (the size of the message block) and the value c
the capacity. The capacity determines the security level of the given hash function.
There is also a JH-like sponge in which the message block is injected twice.
The main problem of using conventional hash functions in constrained environments is their large internal state. SHA-3 uses a 1600 bit IS, and its most compact
hardware implementation needs 5522 GE [471] on 0.13 µm technology. On the
other hand, SHA-256 has a smaller IS (256 bit), but one of its smaller hardware
implementations uses 10,868 GE [211] on 0.35 µm technology.
Lightweight hash functions can have smaller internal state and digest sizes (for
applications where collision resistance is not required), better performance on short
messages, small hardware implementations, etc. In some cases, for example tagbased applications, there is a need only for the one-way property. Also, most tag
protocols require hashing of small messages, usually much less than 256 bits.
Précédent

- 45/268

Suivant