Académique Documents
Professionnel Documents
Culture Documents
AES-NI (AEGIS)
Fast
SIMD (MORUS)
Mode (JAMBU)
Lightweight
Dedicated (ACORN)
easy to analyze x2
secure up to birthday bound
AES
2.5 times faster than AES (4R)
Tag: 128-bit
DIAC 2014 AEGIS 8
AEGIS-128
S0 S1 S2 S3 S4 K IV
xi
AES(1R) AES(1R) AES(1R) AES(1R) AES(1R) K IV AEGIS
(10R)
x1 AEGIS
(1R)
x2 AEGIS
(1R)
larger state: 5 x 128 bits
length
but simpler operation: 1 AES round
still easy to analyze AEGIS
(7R)
Si ,1 (Si , 2 & Si ,3 ) Si , 4
DIAC 2014 AEGIS 14
AEGIS: Security
Randomness of keystream
Recent results (Minaud, SAC 2014)
AEGIS-128
2130+ keystream bits for distinguishing
AEGIS-256
2180+ keystream bits for distinguishing
AEGIS-128L
So far, no results (expected to be strong)
Simple design
Likely the fastest on Haswell processors
Targeting platforms with AES-NI
Also fast for short messages
Strong in security