Dumbo, Jumbo, and Delirium: Parallel Authenticated Encryption for the Lightweight Circus

Dumbo, Jumbo, and Delirium: Parallel Authenticated Encryption for the Lightweight Circus
复制标题

DOI:
10.13154/tosc.v2020.is1.5-30
复制
发表时间:
2020-01-01
影响因子:
3.5
通讯作者:
Mennink, Bart
Mennink, Bart
中科院分区:
其他
文献类型:
--
作者:
Beyne, Tim;Chen, Yu Long;Mennink, Bart

文献摘要

被引文献

相似文献

随着越来越多的设备连接到互联网的趋势,认证加密已经成为保护这些设备和服务器之间以及这些设备之间的直接通信的主要支柱。实际使用的大多数认证加密算法都是为了在现代高端设备上表现良好而开发的,但不一定适合在资源受限的设备上使用。我们提出了一个轻量级的认证加密方案,称为大象。Elephant保留了GCM的优点,例如并行性,但针对资源受限设备的需求进行了定制。Elephant的两个最小的实例Dumbo和Jumbo分别基于160位和176位Spongent排列,特别适合硬件; Elephant的最大实例Delirium基于200位Spongent排列,并面向软件使用开发。所有三个实例都是可并行的,具有小的状态大小,同时实现高级别的安全性,并且通过设计是恒定时间的。
With the trend to connect more and more devices to the Internet, authenticated encryption has become a major backbone in securing the communication, not only between these devices and servers, but also the direct communication among these devices. Most authenticated encryption algorithms used in practice are developed to perform well on modern high-end devices, but are not necessarily suited for usage on resource-constrained devices. We present a lightweight authenticated encryption scheme, called Elephant. Elephant retains the advantages of GCM such as parallelism, but is tailored to the needs of resource-constrained devices. The two smallest instances of Elephant, Dumbo and Jumbo, are based on the 160-bit and 176-bit Spongent permutation, respectively, and are particularly suited for hardware; the largest instance of Elephant, Delirium, is based on 200-bit Keccak and is developed towards software use. All three instances are parallelizable, have a small state size while achieving a high level of security, and are constant time by design.