Abstract

Weaknesses in the Grain-128AEAD key re-introduction, as part of the
cipher initialization, are analyzed and discussed. We consider and analyze
several possible alternatives for key re-introduction and identify weaknesses, or potential weaknesses, in them. Our results show that it seems
favorable to separate the state initialization, the key re-introduction, and
the A/R register initialization into three separate phases. Based on this,
we propose a new cipher initialization and update the cipher version to
Grain-128AEADv2. It can be noted that previously reported and published analysis of the initialization remains valid also for this new versi
Original languageEnglish
PublisherARMGHM / NIST - CNRS
Publication statusPublished - 2021

Subject classification (UKÄ)

  • Computer Sciences

Fingerprint

Dive into the research topics of 'Grain-128AEAD, Round 3 Tweak and Motivation'. Together they form a unique fingerprint.

Cite this