LOTUS and LOCUS AEAD: Hardware Benchmarking and Security Analysis

LOTUS and LOCUS AEAD: Hardware Benchmarking and Security Analysis
复制标题

LOTUS 和 LOCUS AEAD:硬件基准测试和安全分析

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Sasaki
Sasaki
中科院分区:
--
文献类型:
--
作者:
Avik Chakraborti;N. Datta;Ashwin Jha;C. M. López;M. Nandi;Yu;Sasaki

文献摘要

被引文献

相似文献

在这篇短文中,我们提出了两种轻量级声发射模式的新设计,称为LOCUS和LOTUS,结构上分别类似于OCB和OTR。这些模式使用更轻的原语(只有64位可调整的分组密码)实现明显更高的AE安全边界。特别是,它们满足NIST的要求:即使使用具有128位密钥的64位原语实例化,也可以实现针对可以进行近264次查询和2128次计算的对手的安全性。这两种模式都是完全可并行的,并提供完整的INT-RUP安全性。我们使用TweGIFT-64 (GIFT分组密码的可调整变体)来实例化我们的AE模式。TweGIFT-64-LOCUS和TweGIFT-64-LOTUS在硬件实现上非常轻量级。为了证明这一点,我们提供了基于FPGA的实现结果,结果表明TweGIFT-64-LOCUS仅消耗257片和690个lut,而TweGIFT-64-LOTUS仅消耗255片和664个lut。我们还对OCB和OTR进行了具体的安全性分析。
In this short note, we propose two new designs for lightweight AE modes, called LOCUS and LOTUS, structurally similar to OCB and OTR, respectively. These modes achieve notably higher AE security bounds with lighter primitives (only a 64-bit tweakable block cipher). Especially, they satisfy the NIST requirements: achieving security against an adversary that can make close to 264 queries and 2128 computations, even when instantiated with a 64-bit primitive with 128-bit key. Both these modes are fully parallelizable and provide full INT-RUP security. We use TweGIFT-64, a tweakable variant of the GIFT block cipher, to instantiate our AE modes. TweGIFT-64-LOCUS and TweGIFT-64-LOTUS are signifcantly light in hardware implementation. To justify, we provide our FPGA based implementation results, which demonstrate that TweGIFT-64-LOCUS consumes only 257 slices and 690 LUTs, while TweGIFT-64-LOTUS consumes only 255 slices and 664 LUTs. We have also provided concrete security analysis both OCB and OTR.