Paper 2015/847

Exploring Energy Efficiency of Lightweight Block Ciphers

Subhadeep Banik, Andrey Bogdanov, and Francesco Regazzoni


In the last few years, the field of lightweight cryptography has seen an influx in the number of block ciphers and hash functions being proposed. One of the metrics that define a good lightweight design is the energy consumed per unit operation of the algorithm. For block ciphers, this operation is the encryption of one plaintext. By studying the energy consumption model of a CMOS gate, we arrive at the conclusion that the total energy consumed during the encryption operation of an r-round unrolled architecture of any block cipher is a quadratic function in r. We then apply our model to 9 well known lightweight block ciphers, and thereby try to predict the optimal value of r at which an r-round unrolled architecture for a cipher is likely to be most energy efficient. We also try to relate our results to some physical design parameters like the signal delay across a round and algorithmic parameters like the number of rounds taken to achieve full diffusion of a difference in the plaintext/key.

Available format(s)
Publication info
Published elsewhere. Minor revision. Selected Areas in Cryptography 2015
AESLightweight Block CipherLow PowerEnergy Circuits
Contact author(s)
subb @ dtu dk
2015-09-02: received
Short URL
Creative Commons Attribution


      author = {Subhadeep Banik and Andrey Bogdanov and Francesco Regazzoni},
      title = {Exploring Energy Efficiency of Lightweight Block Ciphers},
      howpublished = {Cryptology ePrint Archive, Paper 2015/847},
      year = {2015},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.