34
A. Mileva et al.
Table 2.5 Lightweight stream ciphers (best known attacks)
Best known attack: data complexity/memory/time
Name
Ref
complexity
A2U2
[173]
Practical key-recovery attack [524] under the KP attack model
210/−/2 24.7
A5/1
[92]
Practical Time-Memory tradeoff attack [92] 2sec KPs/ 2 48
preprocessing steps to compute 300GB/ 2 24
BEAN
[350]
Distinguishing attack [13] with 2 17 keystream bits
CAR30
[172]
−
CAvium
[511]
−
ChaCha
[79]
Multi-bit differential attack [143]: 2 28 / −/ 2 233 on 7 rounds
E0
[96]
Practical key-recovery attack [381] using the first 24 bits of
2 23.8 frames and 2 38 computations
Enocoro
[574, 575] −
Fruit-80
[228]
−
Grain
[266, 267] Fast near collision attack [595]: 2 19 / 2 28 / 2 75.7 on Grainv1
LILLE
[53]
−
LIZARD
[253]
Distinguishing attack [52]: −/2 76.6 /2 51.5 random IV enc
MICKEY 2.0 [48]
Practical related key attack [179] with 65/113 related (K,?IV)
pairs and 0.9835/0.9714 success rate
Plantlet
[421]
Distinguishing attack [422]
Rabbit
[98]
Differential fault analysis [330] with 128 − 256 faults: −/2 41.6
B/2 38
RAKAPOSHI [148]
Related key attack [297]: 2 38 chosen IVs/−/ 2 41
Salsa20
[80]
Multi-bit differential attack [143]: 2 96 / −/ 2 244.9 on 8 rounds
SNOW 3G
[204]
Multiset distinguisher [90]: 2 8 on 13 rounds
Sprout
[27]
Many, e.g., key recovery attack [50]: −/−/2 66.7 enc.
Trivium
[127]
Key-recovery attack [224]: 2 77 on 855 rounds
Quavium
[555]
−
WG-8
[207]
Related key attacks [180] with one related key 2 52 chosen
IVs/−/ 2 53.32
ZUC (v 1.6)
−
KP—Known Plaintext
Tables 2.6 and 2.7 list the cryptographic and implementation properties of
the known lightweight hash functions. ARMADILLO is considered insecure.
Lesamnta-LW, PHOTON, and SPONGENT are part of the ISO/IEC 29192-5:2016
standard.
2.2.4 Message Authentication Codes
A message authentication code (MAC) protects the integrity and authenticity of
a given message, by generating a tag from the message and a secret key. MAC
Précédent

- 48/268

Suivant