Masking the Lightweight Authenticated Ciphers ACORN and Ascon in Software

Alexandre Adomnicai and Jacques J.A. Fournier and Laurent Masson

Abstract: The ongoing CAESAR competition aims at finding authenticated encryption schemes that offer advantages over AES-GCM for several use-cases, including lightweight applications. ACORN and Ascon are the two finalists for this profile. Our paper compares these two candidates according to their resilience against differential power analysis and their ability to integrate countermeasures against such attacks. Especially, we focus on software implementations and provide benchmarks for several security levels on an ARM Cortex-M3 embedded microprocessor.

Category / Keywords: ACORN, Ascon, DPA, Masking

Original Publication (with minor differences): BalkanCryptSec 2018

Date: received 26 Jul 2018, last revised 3 Aug 2018

Contact author: alex adomnicai at gmail com

Note: Fixed a mistake on the number of ACORN's state updates to target so that a DPA returns an unique key hypothesis (82 instead of 81).

Version: 20180803:061246 (All versions of this report)

