Paper 2010/152

Secure and Fast Implementations of Two Involution Ciphers

Billy Bob Brumley

Abstract

Anubis and Khazad are closely related involution block ciphers. Building on two recent AES software results, this work presents a number of constant-time software implementations of Anubis and Khazad for processors with a byte-vector shuffle instruction, such as those that support SSSE3. For Anubis, the first is serial in the sense that it employs only one cipher instance and is compatible with all standard block cipher modes. Efficiency is largely due to the S-box construction that is simple to realize using a byte shuffler. The equivalent for Khazad runs two parallel instances in counter mode. The second for each cipher is a parallel bit-slice implementation in counter mode.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. Unknown where it was published
Keywords
AnubisKhazadinvolution ciphersblock cipherssoftware implementationtiming attacks
Contact author(s)
billy brumley @ tkk fi
History
2010-11-10: revised
2010-03-22: received
See all versions
Short URL
https://ia.cr/2010/152
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2010/152,
      author = {Billy Bob Brumley},
      title = {Secure and Fast Implementations of Two Involution Ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2010/152},
      year = {2010},
      url = {https://eprint.iacr.org/2010/152}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.