Paper 2026/547

Dialga: A Family of Low-Latency Tweakable Block Ciphers using Multiple Linear Layers (Full Version)

Subhadeep Banik, University of Lugano, Lugano, Switzerland
Tatsuya Ishikawa, The University of Osaka, Suita, Japan
Takanori Isobe, The University of Osaka, Suita, Japan
Ryoma Ito, NICT, Koganei, Japan, The University of Osaka, Suita, Japan
Kazuhiko Minematsu, NEC, Kawasaki, Japan
Kazuma Nakata, University of Hyogo, Kobe, Japan
Mostafizar Rahman, Kyoto University, Kyoto, Japan
Kosei Sakamoto, Mitsubishi Electric Corporation, Kamakura, Japan, The University of Osaka, Suita, Japan
Abstract

In this paper, we propose Dialga, a family of low-latency tweakable block ciphers designed to support 128/256-bit tweaks and 256-bit keys. Dialga achieves significantly small latency by leveraging multiple novel strategies. These include the use of multiple linear layers with efficient cell permutations, which enhance security against differential and linear attacks with negligible hardware overhead. We also identify the optimal choice of S-boxes for these permutations using state-of-the-art evaluation methods by SAT, enabling us to further reduce the delay of the round function. Besides, we design a reflection tweakey schedule that ensures strong security in the related-tweak setting and allows for encryption and decryption without delay overhead, reducing the circuit area. We conducted comprehensive hardware benchmarks involving Dialga and other primitives. As a result, Dialga achieves nearly half the delay of QARMAv2, while achieving approximately a 40% reduction in area, with the same claimed security.  We also demonstrate that Dialga enables an efficient low-latency TBC-based authenticated encryption instantiation: Flat-ΘCB based on Dialga compares favorably with AES-256-GCM in hardware, achieves substantially lower delay than AES-256-GCM.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
A major revision of an IACR publication in TOSC 2025
DOI
10.46586/tosc.v2025.i4.70-124
Keywords
Ultra-low latencyTweakable block cipherMultiple linear layersMemory encryptionBeyond 5G (B5G)AE
Contact author(s)
subhadeep banik @ usi ch
t ishikawa037 @ gmail com
takanori isobe @ ist osaka-u ac jp
itorym @ nict go jp
k-minematsu @ nec com
marokazu670 @ gmail com
mrahman454 @ gmail com
sakamoto kosei @ dc mitsubishielectric co jp
History
2026-03-22: approved
2026-03-19: received
See all versions
Short URL
https://ia.cr/2026/547
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/547,
      author = {Subhadeep Banik and Tatsuya Ishikawa and Takanori Isobe and Ryoma Ito and Kazuhiko Minematsu and Kazuma Nakata and Mostafizar Rahman and Kosei Sakamoto},
      title = {Dialga: A Family of Low-Latency Tweakable Block Ciphers using Multiple Linear Layers (Full Version)},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/547},
      year = {2026},
      doi = {10.46586/tosc.v2025.i4.70-124},
      url = {https://eprint.iacr.org/2026/547}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.