Paper 2021/751

Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction

Martin Hell, Thomas Johansson, Alexander Maximov, Willi Meier, and Hirotaka Yoshida

Abstract

Properties of the Grain-128AEAD key re-introduction, as part of the cipher initialization, are analyzed and discussed. We consider and analyze several possible alternatives for key re-introduction and identify weaknesses, or potential weaknesses, in them. Our results show that it seems favorable to separate the state initialization, the key re-introduction, and the $A/R$ register initialization into three separate phases. Based on this, we propose a new cipher initialization and update the cipher version to Grain-128AEADv2. It can be noted that previously reported and published analysis of the cipher remains valid also for this new version.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint. MINOR revision.
Keywords
Grain-128AEADv2stream ciphersNISTdifferentials
Contact author(s)
martin hell @ eit lth se
History
2021-06-07: received
Short URL
https://ia.cr/2021/751
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2021/751,
      author = {Martin Hell and Thomas Johansson and Alexander Maximov and Willi Meier and Hirotaka Yoshida},
      title = {Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction},
      howpublished = {Cryptology ePrint Archive, Paper 2021/751},
      year = {2021},
      note = {\url{https://eprint.iacr.org/2021/751}},
      url = {https://eprint.iacr.org/2021/751}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.