Paper 2025/1180
Cryptanalysis of the Authenticated Stream Cipher HiAE
Abstract
We describe key-recovery attacks on the authenticated stream cipher HiAE, which was recently proposed by Huawei for future high-throughput communication networks such as 6G, setting a new throughput performance record. HiAE uses a 2048-bit state, a 256-bit key and produces 128-bit tags, targeting 256-bit security against key and state recovery. As a nonce-based scheme for authenticated encryption with associated data (AEAD), it relies on the uniqueness of the nonce per key for these security claims. Our analysis indicates that a complete recovery of the 256-bit key of HiAE is possible with a complexity of $2^{128}$ data and at most $2^{129}$ time. This key-recovery attack goes beyond the known distinguishability results for online AEAD with longer keys than tags (Khairallah, CiC 2024). Our attack model is nonce-respecting and uses decryption queries, similar to the previous cryptanalysis of the AEAD schemes COFB (Khairallah, ToSC 2022) and particularly Rocca (Hosoyamada et al., ToSC 2022). Since the security claims for HiAE exclude repeated tag guessing for key recovery, our attack allows an arbitrary trade-off in the number of queries $1\leq q \leq 2^{128}$ such that the ratio of total cost to success probability is always at most $2^{129}$. Our results also imply that the key-dependent initialization countermeasure proposed for Rocca and employed in HiAE to achieve 256-bit security against key-recovery attacks is not sufficient by itself for this design strategy. We describe further complete key-recovery attacks in the nonce-misuse and release of unverified plaintext (RUP) settings which require only a small constant number of repeated nonces or unverified decryption queries, respectively. We furthermore discuss the applicability of our attack to other NFSR-based AEAD schemes using the AES round function and suggest possible countermeasures.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- A minor revision of an IACR publication in TOSC 2026
- DOI
- 10.46586/tosc.ak5womx4wo3r
- Keywords
- CryptanalysisHiAEAES-based AEADAuthenticated Stream CiphersNFSRKey-recovery AttackAuthenticated Encryption
- Contact author(s)
-
alexander bille @ uni-marburg de
tischhauser @ informatik uni-marburg de - History
- 2026-06-16: revised
- 2025-06-23: received
- See all versions
- Short URL
- https://ia.cr/2025/1180
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1180,
author = {Alexander Bille and Elmar Tischhauser},
title = {Cryptanalysis of the Authenticated Stream Cipher {HiAE}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1180},
year = {2025},
doi = {10.46586/tosc.ak5womx4wo3r},
url = {https://eprint.iacr.org/2025/1180}
}