Paper 2025/2186

BEANIE – A 32-bit Cipher for Cryptographic Mitigations against Software Attacks

Simon Gerhalter, Graz University of Technology
Samir Hodžić, NXP Semiconductors
Marcel Medwed, NXP Semiconductors
Marcel Nageler, Graz University of Technology
Artur Folwarczny, NXP Semiconductors
Ventzi Nikov, NXP Semiconductors
Jan Hoogerbrugge, NXP Semiconductors
Tobias Schneider, NXP Semiconductors
Gary McConville, NXP Semiconductors
Maria Eichlseder, Graz University of Technology
Abstract

In modern CPU architectures, various security features to mitigate software attacks can be found. Examples of such features are logical isolation, memory tagging or shadow stacks. Basing such features on cryptographic isolation instead of logical checks can have many advantages such as lower memory overhead and more robustness against misconfiguration or low-cost physical attacks. The disadvantage of such an approach is however that the cipher that has to be introduced has a severe impact on the system performance, either in terms of additional cycles or a decrease of the maximum achievable frequency. Finally, as of today, there is no suitable low-latency cipher design available for encrypting 32-bit words as is common in microcontrollers. In this paper, we propose a 32-bit tweakable block cipher tailored to memory encryption for microcontroller units. We optimize this cipher for low latency, which we achieve by a careful selection of components for the round function and leveraging an attack scenario similar to the one used to analyze the cipher SCARF. To mitigate some attack vectors introduced by this attack scenario, we deploy a complex tweak-key schedule. Due to the shortage of suitable 32-bit designs, we compare our design to various low-latency ciphers with different block sizes. Our hardware implementation shows competitive latency numbers.

Note: Code can be found at https://github.com/isec-tugraz/beanie_cipher/

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in TOSC 2025
DOI
10.46586/tosc.v2025.i4.31-69
Keywords
Low-latency block cipherMemory encryptionTweakable block cipher
Contact author(s)
simon gerhalter @ tugraz at
samir hodzic @ nxp com
marcel medwed @ nxp com
marcel nageler @ tugraz at
artur folwarczny @ nxp com
ventzi nikov @ nxp com
jan hoogerbrugge @ nxp com
tobias schneider @ nxp com
gary mcconville @ nxp com
maria eichlseder @ tugraz at
History
2026-01-14: revised
2025-12-02: received
See all versions
Short URL
https://ia.cr/2025/2186
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2186,
      author = {Simon Gerhalter and Samir Hodžić and Marcel Medwed and Marcel Nageler and Artur Folwarczny and Ventzi Nikov and Jan Hoogerbrugge and Tobias Schneider and Gary McConville and Maria Eichlseder},
      title = {{BEANIE} – A 32-bit Cipher for Cryptographic Mitigations against Software Attacks},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2186},
      year = {2025},
      doi = {10.46586/tosc.v2025.i4.31-69},
      url = {https://eprint.iacr.org/2025/2186}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.