2018MADOC (University of Mannheim)Open access

Lightweight symmetric cryptography

Vasily Mikhalev

Open full text 0 citations

Abstract

The Internet of Things is one of the principal trends in information \ntechnology nowadays. The main idea behind this concept is that devices \ncommunicate autonomously with each other over the Internet. Some of \nthese devices have extremely limited resources, such as power and energy, \n available time for computations, amount of silicon to produce the chip, \ncomputational power, etc. Classical cryptographic primitives are often \ninfeasible for such constrained devices. The goal of lightweight \ncryptography is to introduce cryptographic solutions with reduced resource \nconsumption, but with a sufficient security level. \nAlthough this research area was of great interest to academia during the \nlast years and a large number of proposals for lightweight cryptographic \nprimitives have been introduced, almost none of them are used in real-word. \nProbably one of the reasons is that, for academia, lightweight usually \nmeant to design cryptographic primitives such that they require minimal \nresources among all existing solutions. This exciting research problem \nbecame an important driver which allowed the academic community to better \nunderstand many cryptographic design concepts and to develop new attacks. \nHowever, this criterion does not seem to be the most important one for \nindustry, where lightweight may be considered as "rightweight". In other \nwords, a given cryptographic solution just has to fit the constraints of \nthe specific use cases rather than to be the smallest. Unfortunately, \nacademic researchers tended to neglect vital properties of the particular \ntypes of devices, into which they intended to apply their primitives. That \nis, often solutions were proposed where the usage of some resources was \nreduced to a minimum. However, this was achieved by introducing new costs \nwhich were not appropriately taken into account or in such a way that the \nreduction of costs also led to a decrease in the security level. Hence, \nthere is a clear gap between academia and industry in understanding what \nlightweight cryptography is. In this work, we are trying to fill some of \nthese gaps. We carefully investigate a broad number of existing lightweight \ncryptographic primitives proposed by academia including authentication \nprotocols, stream ciphers, and block ciphers and evaluate their \napplicability for real-world scenarios. We then look at how individual \ncomponents of design of the primitives influence their cost and summarize \nthe steps to be taken into account when designing primitives for concrete \ncost optimization, more precisely - for low energy consumption. Next, we \npropose new implementation techniques for existing designs making them more \nefficient or smaller in hardware without the necessity to pay any \nadditional costs. After that, we introduce a new stream cipher design \nphilosophy which enables secure stream ciphers with smaller area size than \never before and, at the same time, considerably higher throughput compared \nto any other encryption schemes of similar hardware cost. To demonstrate \nthe feasibility of our findings we propose two ciphers with the smallest \narea size so far, namely Sprout and Plantlet, and the most energy \nefficient encryption scheme called Trivium-2. Finally, this thesis solves \na concrete industrial problem. Based on standardized cryptographic \nsolutions, we design an end-to-end data-protection scheme for low power \nnetworks. This scheme was deployed on the water distribution network in the \nCity of Antibes, France.

Open-access reader

About this research paper

What this paper is about

The Internet of Things is one of the principal trends in information \ntechnology nowadays. The main idea behind this concept is that devices \ncommunicate autonomously with each other over the Internet. Some of \nthese devices have extremely limited resources, such as power and energy, \n available time for computations, amount of silicon to produce the chip, \ncomputational power, etc. Classical cryptographic primitives are often \ninfeasible for such constrained devices. The goal of lightweight \ncryptography is to introduce cryptographic solutions with reduced resource \nconsumption, but with a sufficient security level. \nAlthough this research area was of great interest to academia during the \nlast years and a large number of proposals for lightweight cryptographic \nprimitives have been introduced, almost none of them are used in real-word. \nProbably one of the reasons is that, for academia, lightweight usually \nmeant to design cryptographic primitives such that they require minimal \nresources among all existing solutions. This exciting research problem \nbecame an important driver which allowed the academic community to better \nunderstand many cryptographic design concepts and to develop new attacks. \nHowever, this criterion does not seem to be the most important one for \nindustry, where lightweight may be considered as "rightweight". In other \nwords, a given cryptographic solution just has to fit the constraints of \nthe specific use cases rather than to be the smallest. Unfortunately, \nacademic researchers tended to neglect vital properties of the particular \ntypes of devices, into which they intended to apply their primitives. That \nis, often solutions were proposed where the usage of some resources was \nreduced to a minimum. However, this was achieved by introducing new costs \nwhich were not appropriately taken into account or in such a way that the \nreduction of costs also led to a decrease in the security level. Hence, \nthere is a clear gap between academia and industry in understanding what \nlightweight cryptography is. In this work, we are trying to fill some of \nthese gaps. We carefully investigate a broad number of existing lightweight \ncryptographic primitives proposed by academia including authentication \nprotocols, stream ciphers, and block ciphers and evaluate their \napplicability for real-world scenarios. We then look at how individual \ncomponents of design of the primitives influence their cost and summarize \nthe steps to be taken into account when designing primitives for concrete \ncost optimization, more precisely - for low energy consumption. Next, we \npropose new implementation techniques for existing designs making them more \nefficient or smaller in hardware without the necessity to pay any \nadditional costs. After that, we introduce a new stream cipher design \nphilosophy which enables secure stream ciphers with smaller area size than \never before and, at the same time, considerably higher throughput compared \nto any other encryption schemes of similar hardware cost. To demonstrate \nthe feasibility of our findings we propose two ciphers with the smallest \narea size so far, namely Sprout and Plantlet, and the most energy \nefficient encryption scheme called Trivium-2. Finally, this thesis solves \na concrete industrial problem. Based on standardized cryptographic \nsolutions, we design an end-to-end data-protection scheme for low power \nnetworks. This scheme was deployed on the water distribution network in the \nCity of Antibes, France.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The Internet of Things is one of the principal trends in information \ntechnology nowadays. The main idea behind this concept is that devices \ncommunicate autonomously with each other over the Internet. Some of \nthese devices have extremely limited resources, such as power and energy, \n available time for computations, amount of silicon to produce the chip, \ncomputational power, etc. Classical cryptographic primitives are often \ninfeasible for such constrained devices. The goal of lightweight \ncryptography is to introduce cryptographic solutions with reduced resource \nconsumption, but with a sufficient security level. \nAlthough this research area was of great interest to academia during the \nlast years and a large number of proposals for lightweight cryptographic \nprimitives have been introduced, almost none of them are used in real-word. \nProbably one of the reasons is that, for academia, lightweight usually \nmeant to design cryptographic primitives such that they require minimal \nresources among all existing solutions. This exciting research problem \nbecame an important driver which allowed the academic community to better \nunderstand many cryptographic design concepts and to develop new attacks. \nHowever, this criterion does not seem to be the most important one for \nindustry, where lightweight may be considered as "rightweight". In other \nwords, a given cryptographic solution just has to fit the constraints of \nthe specific use cases rather than to be the smallest. Unfortunately, \nacademic researchers tended to neglect vital properties of the particular \ntypes of devices, into which they intended to apply their primitives. That \nis, often solutions were proposed where the usage of some resources was \nreduced to a minimum. However, this was achieved by introducing new costs \nwhich were not appropriately taken into account or in such a way that the \nreduction of costs also led to a decrease in the security level. Hence, \nthere is a clear gap between academia and industry in understanding what \nlightweight cryptography is. In this work, we are trying to fill some of \nthese gaps. We carefully investigate a broad number of existing lightweight \ncryptographic primitives proposed by academia including authentication \nprotocols, stream ciphers, and block ciphers and evaluate their \napplicability for real-world scenarios. We then look at how individual \ncomponents of design of the primitives influence their cost and summarize \nthe steps to be taken into account when designing primitives for concrete \ncost optimization, more precisely - for low energy consumption. Next, we \npropose new implementation techniques for existing designs making them more \nefficient or smaller in hardware without the necessity to pay any \nadditional costs. After that, we introduce a new stream cipher design \nphilosophy which enables secure stream ciphers with smaller area size than \never before and, at the same time, considerably higher throughput compared \nto any other encryption schemes of similar hardware cost. To demonstrate \nthe feasibility of our findings we propose two ciphers with the smallest \narea size so far, namely Sprout and Plantlet, and the most energy \nefficient encryption scheme called Trivium-2. Finally, this thesis solves \na concrete industrial problem. Based on standardized cryptographic \nsolutions, we design an end-to-end data-protection scheme for low power \nnetworks. This scheme was deployed on the water distribution network in the \nCity of Antibes, France.

Key concepts: Cryptography, Cryptographic primitive, Computer science, Computer security, Principal (computer security), The Internet, Resource (disambiguation), Theoretical computer science

Related papers

Back to paper searchBrowse research topicsOriginal source
Lightweight symmetric cryptography — Research Paper | ScholarLens