The QARMA Block Cipher Family Almost MDS Matrices Over Rings With Zero Divisors, Nearly Symmetric Even-Mansour Constructions With Non-Involutory Central Rounds, and Search Heuristics for Low-Latency S-Boxes

The QARMA Block Cipher Family Almost MDS Matrices Over Rings With Zero Divisors, Nearly Symmetric Even-Mansour Constructions With Non-Involutory Central Rounds, and Search Heuristics for Low-Latency S-Boxes
复制标题

DOI:
10.13154/tosc.v2017.i1.4-44
复制
发表时间:
2017-01-01
影响因子:
3.5
通讯作者:
Avanzi, Roberto
Avanzi, Roberto
中科院分区:
其他
文献类型:
--
作者:
Avanzi, Roberto

文献摘要

被引文献

相似文献

本文介绍了QARMA,一个新的轻量级可调分组密码家族,它主要应用于存储器加密、用于硬件辅助防止软件开发的极短标记的生成以及密钥哈希函数的构造等方面,QARMA的设计灵感来自于反射密码,如PRINCE和MANTIS,它在PRINCE中增加了一个可调输入。然而,QARMA与之前的反射器构造的不同之处在于,它是三轮Even-Mans方案而不是FX构造,并且它的中间置换是非对合的且带键的。我们介绍和分析了一个家庭的几乎MDS矩阵定义在一个环上的零因子,使我们能够在其操作中编码旋转,同时保持最小的延迟与{0,1}-矩阵。所有这些设计选择的目的是加强密码对各种类型的攻击。我们还描述了新的S盒搜索算法,旨在最小化关键路径。QARMA存在于64位和128位的块大小,其中块和调整大小是相等的,密钥是块的两倍长。我们认为,QARMA提供了足够的安全裕度内所提到的应用程序所确定的约束,最后,我们提出了一种技术,通过使用,例如,一个通用的哈希函数,它也可以用来加强QARMA的安全性,以延长调整的长度。
This paper introduces QARMA, a new family of lightweight tweakable block ciphers targeted at applications such as memory encryption, the generation of very short tags for hardware-assisted prevention of software exploitation, and the construction of keyed hash functions.QARMA is inspired by reflection ciphers such as PRINCE, to which it adds a tweaking input, and MANTIS. However, QARMA differs from previous reflector constructions in that it is a three-round Even-Mans our scheme instead of a FX-construction, and its middle permutation is non-involutory and keyed. We introduce and analyse a family of Almost MDS matrices defined over a ring with zero divisors that allows us to encode rotations in its operation while maintaining the minimal latency associated to {0, 1}-matrices. The purpose of all these design choices is to harden the cipher against various classes of attacks.We also describe new S-Box search heuristics aimed at minimising the critical path.QARMA exists in 64- and 128-bit block sizes, where block and tweak size are equal, and keys are twice as long as the blocks.We argue that QARMA provides sufficient security margins within the constraints determined by the mentioned applications, while still achieving best-in-class latency.Implementation results on a state-of-the art manufacturing process are reported.Finally, we propose a technique to extend the length of the tweak by using, for instance, a universal hash function, which can also be used to strengthen the security of QARMA.