IP Library Granted Patent US 12,470,376
Granted Patent B2
US 12,470,376 · App. 18/412,267 · Granted Nov 11, 2025

Cryptographic system for post-quantum cryptographic operations

Inventor: Markku-Juhani Olavi Saarinen (Oxford, GB)
Assignee: PQShield Ltd
H04L9/0852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,376
App. No.
18/412,267
Granted
Nov 11, 2025
Kind
B2
Abstract

Certain examples described herein relate to at least a cryptographic system and a method of operating a cryptographic system. The cryptographic system may be implemented as a co-processor for performing post-quantum cryptographic functions. The cryptographic system has a set of bus interfaces for coupling to an external computing system, a cryptographic math unit and a control unit. The cryptographic math unit in certain examples is adapted to provide one or more masked modes of operation that secure the cryptographic operations against side-channel and non-invasive attacks. The method of operating a cryptographic system involves annotating secret data and tracking those annotations through one or more arithmetic operations.

Claims (58)

1 . A cryptographic system to perform post-quantum cryptographic operations for a communicatively-coupled computing system, the cryptographic system being separate from the communicatively-coupled computing system and comprising:

a set of bus interfaces for communicatively coupling the cryptographic system to one or more system buses of the computing system;

a cryptographic math unit; and

a control unit comprising at least one processor and memory to control the cryptographic math unit, wherein the control unit is communicatively coupled to the set of bus interfaces via a first internal bus and is communicatively coupled to the cryptographic math unit via a second internal bus, wherein the first and second internal buses do not allow access to internal cryptographic data of the cryptographic math unit during the cryptographic operations,

wherein the cryptographic math unit comprises:

a matrix memory to store a multi-dimensional array of data;

an address generator configured to receive control signals from the control unit and to control access to data within the matrix memory;

an arithmetic unit to perform a set of defined arithmetic operations upon data within the matrix memory as accessed using the address generator; and

a permutation unit configured to generate a random bit sequence, wherein the permutation unit is controlled by the control unit and is communicatively coupled to the arithmetic unit,

wherein the cryptographic system is configured to perform masked arithmetic computations by decomposing secret data values into a plurality of data shares, the control unit being configured to control the arithmetic unit and the address generator to apply at least one of the set of defined arithmetic operations as a plurality of independent linear operations on the respective plurality of data shares.

2 . The cryptographic system of claim 1 , wherein the cryptographic system comprises a masked mode of operation and, for the masked mode of operation, is configured to:

receive, via the set of bus interfaces, an instruction from the communicatively-coupled computing system to perform a masked arithmetic computation as a single atomic operation;

determine, at the control unit, a first set of control signals to control access to data within the matrix memory and a second set of control signals to control at least one operation of the arithmetic unit to perform the masked arithmetic computation;

decompose secret data values stored within the matrix memory into a plurality of masked data shares by applying one or more random bit sequences from the permutation unit to the secret data values; and

repeatedly apply the at least one operation on each of the plurality of data shares using the arithmetic unit to perform the masked arithmetic computation, the at least one operation being applied as a plurality of independent linear operations.

3 . The cryptographic system of claim 2 , wherein the cryptographic system is configured to, for the masked mode of operation:

retrieve an encrypted secret data value via the set of bus interfaces; and

decrypt the encrypted secret data value and store the decrypted data value in the matrix memory for decomposition into the masked data shares,

wherein a result of the at least one operation is only exported to the communicatively-coupled computing system in an encrypted form.

4 . The cryptographic system of claim 1 , wherein the permutation unit performs an ASCON permutation.

5 . The cryptographic system of claim 1 , wherein the control unit comprises a set of condition-free instructions that are stored in the memory and executed by the processor.

6 . The cryptographic system of claim 1 , wherein the permutation unit comprises:

an Extendable-Output Function-XOF-unit to apply cryptographic operations to generate an indefinite-length output stream,

wherein the XOF unit is controlled by the control unit and is communicatively coupled to the arithmetic unit.

7 . The cryptographic system of claim 6 , wherein the XOF unit is configured to perform one or more of: a cryptographic absorb operation, a cryptographic squeeze operation, a cryptographic sampling operation and a cryptographic random masking operation.

8 . The cryptographic system of claim 6 , wherein the XOF unit comprises a n-bit cryptographic state that is separated into a plurality of data shares for masked arithmetic computations.

9 . The cryptographic system of claim 6 , wherein the cryptographic system is configured to compute one or more of Winternitz hash chains and Merkle tree data.

10 . The cryptographic system of claim 1 , wherein the cryptographic system is configured to compute hash-based signatures by iteratively hashing data stored in the matrix memory.

11 . The cryptographic system of claim 1 , wherein the cryptographic system is configured to perform one or more of:

key establishment functions including one or more of encryption and decryption;

digital signature functions including one or more of digital signature generation and digital signature verification; and

stateful hash-based signatures.

12 . The cryptographic system of claim 11 , wherein the cryptographic system is configured to:

implement one or more of: lattice post-quantum key establishment functions and code-based post-quantum key establishment functions;

implement one or more of: lattice post-quantum digital signature functions, code-based post-quantum digital signature functions, hash-based post-quantum digital signature functions, and multivariate post-quantum digital signature functions; and

implement hierarchical signature system functions.

13 . The cryptographic system of claim 1 , wherein the arithmetic unit comprises an arithmetic pipeline unit that receives control data indicating a selected operation to perform from the control unit and that performs the selected operation as a plurality of stages over time.

14 . The cryptographic system of claim 13 , wherein the plurality of stages comprise a plurality of parallel processing streams, the plurality of parallel processing streams receiving data accessed from the matrix memory.

15 . The cryptographic system of claim 1 , wherein the processor of the control unit is configured to receive vector instructions via the set of bus interfaces and convert the vector instructions into control instructions for vector operations for the cryptographic math unit.

16 . The cryptographic system of claim 1 , wherein the set of bus interfaces comprise:

a set of control registers writable by at least one processor of the communicatively-coupled computing system; and

a set of cryptographic registers for secret cryptographic data.

17 . The cryptographic system of claim 1 , wherein the control unit is configured to convert from a first masking format to a second masking format.

18 . The cryptographic system of claim 1 , wherein the control unit is configured to implement one or more of Boolean masking and arithmetic masking.

19 . A method of operating a cryptographic system, the cryptographic system being separate from a communicatively-coupled computing system, the method comprising:

receiving, via a set of bus interfaces of the cryptographic system, an instruction from the communicatively-coupled computing system to perform a masked arithmetic computation as a single atomic operation;

accessing, by a control unit of the cryptographic system comprising at least one processor and memory, the instruction as written to the set of bus interfaces;

determining, at the control unit, a first set of control signals to control access to data within a matrix memory of the cryptographic system and a second set of control signals to control at least one operation of an arithmetic unit of the cryptographic system to perform the masked arithmetic computation;

decomposing secret data values stored within the matrix memory into a plurality of masked data shares by applying one or more random bit sequences from a permutation unit of the cryptographic system to the secret data values; and

repeatedly applying, using the first and second set of control signals, the at least one operation on each of the plurality of data shares using the arithmetic unit to perform the masked arithmetic computation, the at least one operation being applied as a plurality of independent linear operations,

wherein during at least said decomposing and said repeatedly applying, the control unit is prevented from accessing the contents of the matrix memory or arithmetic unit.

20 . The method of claim 19 , comprising:

exporting a non-secret result of the masked arithmetic computation to the communicatively-coupled computing system via the set of bus interfaces of the cryptographic system,

including, in a case where the masked arithmetic computation provides a secret result, encrypting the secret result prior to exporting.

21 . The method of claim 19 , comprising:

retrieving an encrypted secret data value via the set of bus interfaces; and

decrypting the encrypted secret data value within the cryptographic system; and

storing the decrypted data value in the matrix memory for decomposition into the masked data shares.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: SAARINEN, MARKKU-JUHANI OLAVI
To: PQSHIELD LTD.
Reel/Frame 066341/0488 →
Priority Claims (1)
GB 2110207 · Jul 15, 2021 · national
Continuity (2)
Continuation PCTGB2022051829 · Jul 14, 2022
Related Publication 20250080334A1 · Mar 6, 2025
References Cited (147)
US 3911330A · Fletcher et al. · 1975 [cited by applicant]
US 4589120A · Mendala · 1986 [cited by applicant]
US 5764765A · Phoenix · 1998 [cited by examiner]
US 6407766B1 · Ramanujan · 2002 [cited by examiner]
US 6748083B2 · Hughes · 2004 [cited by examiner]
US 7437081B2 · Mitchell · 2008 [cited by examiner]
US 8194855B2 · Shantz · 2012 [cited by examiner]
US 8538012B2 · Dixon et al. · 2013 [cited by applicant]
US 8572410B1 · Tkacik · 2013 [cited by examiner]
US 8761401B2 · Sprunk · 2014 [cited by examiner]
US 8782774B1 · Pahl · 2014 [cited by examiner]
US 8855316B2 · Wiseman · 2014 [cited by examiner]
US 8971538B1 · Marr · 2015 [cited by examiner]
US 9628268B2 · Kiang · 2017 [cited by examiner]
US 9772845B2 · Yap · 2017 [cited by examiner]
US 9960465B2 · Dudley · 2018 [cited by examiner]
US 10038550B2 · Gopal · 2018 [cited by examiner]
US 10057058B2 · Murakami · 2018 [cited by examiner]
US 10313129B2 · Gopal · 2019 [cited by examiner]
US 20020040429A1 · Dowling · 2002 [cited by examiner]
US 20030084309A1 · Kohn · 2003 [cited by examiner]
US 20050138352A1 · Gauvreau · 2005 [cited by examiner]
US 20070065154A1 · Luo · 2007 [cited by examiner]
US 20070076884A1 · Wellbrock · 2007 [cited by examiner]
US 20070195774A1 · Sherman · 2007 [cited by examiner]
US 20080019524A1 · Kim · 2008 [cited by examiner]
US 20080056488A1 · Motoyama · 2008 [cited by examiner]
US 20080229116A1 · Dixon · 2008 [cited by examiner]
US 20080298583A1 · Ahmed · 2008 [cited by examiner]
US 20090254718A1 · Biscondi et al. · 2009 [cited by applicant]
US 20100115237A1 · Brewer · 2010 [cited by examiner]
US 20100128872A1 · Cordery · 2010 [cited by examiner]
US 20100146296A1 · Kim · 2010 [cited by examiner]
US 20100195820A1 · Frank · 2010 [cited by examiner]
US 20100235417A1 · Baek · 2010 [cited by examiner]
US 20100289943A1 · Tokoro · 2010 [cited by examiner]
US 20110206204A1 · Sychev · 2011 [cited by examiner]
US 20110213979A1 · Wiseman · 2011 [cited by examiner]
US 20120076293A1 · Smith · 2012 [cited by examiner]
US 20130275722A1 · Yap · 2013 [cited by examiner]
US 20140010234A1 · Patel · 2014 [cited by examiner]
US 20140068765A1 · Choi · 2014 [cited by examiner]
US 20140095844A1 · Gopal · 2014 [cited by examiner]
US 20140133652A1 · Oshida · 2014 [cited by examiner]
US 20140189369A1 · Wolrich · 2014 [cited by examiner]
US 20140254792A1 · Gammel · 2014 [cited by examiner]
US 20150149788A1 · Gupta · 2015 [cited by examiner]
US 20160080143A1 · Kindarji · 2016 [cited by examiner]
US 20160241396A1 · Fu · 2016 [cited by examiner]
US 20160359626A1 · Fu · 2016 [cited by examiner]
US 20160366094A1 · Mason · 2016 [cited by examiner]
US 20170018013A1 · Faust · 2017 [cited by examiner]
US 20170109162A1 · Yap · 2017 [cited by examiner]
US 20170142081A1 · Jutla · 2017 [cited by examiner]
US 20170180131A1 · Ghosh · 2017 [cited by examiner]
US 20170214525A1 · Zhao · 2017 [cited by examiner]
US 20170230173A1 · Choi · 2017 [cited by examiner]
US 20170242590A1 · Gokhale · 2017 [cited by examiner]
US 20180063100A1 · Peeters · 2018 [cited by examiner]
US 20180157489A1 · Yap et al. · 2018 [cited by applicant]
US 20180176091A1 · Yoon · 2018 [cited by examiner]
US 20180212761A1 · Bilgin · 2018 [cited by examiner]
US 20190036821A1 · Levy · 2019 [cited by examiner]
US 20190109703A1 · Gueron · 2019 [cited by examiner]
US 20190146700A1 · Gschwind · 2019 [cited by examiner]
US 20190349392A1 · Wetterwald · 2019 [cited by examiner]
US 20200084222A1 · William · 2020 [cited by examiner]
CN 103812643A · 2014 [cited by applicant]
CN 107800532A · 2018 [cited by applicant]
EP 801477A1 · 1997 [cited by applicant]
EP 955590A1 · 1999 [cited by applicant]
EP 992887A2 · 2000 [cited by applicant]
JP H03251890A · 1991 [cited by applicant]
JP 20010195555A · 2001 [cited by applicant]
JP 2002107691A · 2002 [cited by applicant]
JP 20050532604A · 2005 [cited by applicant]
JP 2008233683A · 2008 [cited by applicant]
JP 2014197169A · 2014 [cited by applicant]
JP 2015014962A · 2015 [cited by applicant]
JP H1031530A · 2019 [cited by applicant]
JP 20190511791A · 2019 [cited by applicant]
KR 1020190020988A · 2019 [cited by applicant]
WO 0176129A2 · 2001 [cited by applicant]
WO 03021863A1 · 2003 [cited by applicant]
WO 2011123575A1 · 2011 [cited by applicant]
WO 2014136594A1 · 2014 [cited by applicant]
WO 2019158641A1 · 2019 [cited by applicant]
WO 2021014125A1 · 2021 [cited by applicant]
WO 2021032946A1 · 2021 [cited by applicant]
Peter Schwabe and Ko Stoffelen. All the AES you need on cortex-m3 and M4.In Roberto Avanzi and Howard M. Heys, editors, Selected Areas in Cryptog-raphy—SAC 2016—23rd International Conference, St. John's, NL, Canada, Aug… [cited by applicant]
Ascon A Family of Authenticated Encryption Algorithms, Jan. 2, 2019. [cited by applicant]
David J. Wheeler and Roger M. Needham. Correction to xtea. InformalManuscript or Report, 1998. URL: https://www.mjos.fi/doc/misc/xxtea.pdf. Oct. 1998. [cited by applicant]
“A cryptographic algorithm based on Linear Feedback Shift Register.” 2010 International Conference on Computer Application and System Modeling (ICCASM 2010). vol. 15. IEEE, 2010. (Year: 2010). [cited by applicant]
“[FIPS 202] “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions”National Institute of Standards and Technology (NIST), Aug. 2015 https://dx.doi.org/10.6028/NIST.FIPS.202”. [cited by applicant]
“Rossi Mélissa: ““Extended Security of Lattice-Based Cryptography””, https://hal.archives-ouvertes.fr/tel-02946399/document” Sep. 10, 2020. [cited by applicant]
Japanese Office Action dated Jul. 1, 2024 for Japanese Patent Application No. 2022-503796. [cited by applicant]
“Blitter Hardware” of the AMIGA Hardware Reference Manual. Addison-Wesley. 1985, Chapter 6. [cited by applicant]
““Crypto-processeur””, pp. 1-190 URL: https://tel.archives-ouvertes.fr/tel-00978472/document sections 3 and 4, 2012. [cited by applicant]
[CC-PP-0084] “Security IC Platform Protection Profile with Augmentation Packages.” Bundesamt für Sicherheit in der Informationstechnik (BSI) reference BSI-CC-PP-0084-2014.https://www.commoncriteriaportal.org/files/ppfil… [cited by applicant]
[SOGIS-AVA] “Application of Attack Potential to Smartcards and Similar Devices.” Version 3.1. (2020). https://www.sogis.eu/documents/cc/domains/sc/JIL-Application-of-Attack-Potential-to-Smartcards-v3-1.pdf Jun. 2020. [cited by applicant]
[SP800-193] “Platform Firmware Resiliency Guidelines.” NIST SP 800-193. (2018). DOI: https://doi.org/10.6028/NIST.SP.800-193 May 2018. [cited by applicant]
[RFC8391] “XMSS: extended Merkle Signature Scheme.” IETF RFC 8391 (2018). DOI: https://doi.org/10.17487/RFC8391 May 2018. [cited by applicant]
[RFC8554] “Leighton-Micali Hash-Based Signatures.” IETF RFC 8554 (2018). DOI: https://doi.org/10.17487/RFC8554, Apr. 2018. [cited by applicant]
[FIPS202] “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions.” FIPS PUB 202. (2015). DOI: https://doi.org/10.6028/NIST.FIPS.202 Aug. 2015. [cited by applicant]
[PQFAQ] ““Post-Quantum Cryptography FAQs / Transition and Migration.””https://csrc.nist.gov/projects/post-quantum-cryptography/faqs Jan. 3, 2017. [cited by applicant]
[CoGrVa14] J. Coron, J. Großschädl, P. K. Vadnala. ““Secure Conversion Between Boolean and Arithmetic Masking of Any Order.””IACR-CHES (2014). http://www.crypto-uni.lu/jscoron/publications/secconvorder.pdf Sep. 23, 2014. [cited by applicant]
[Co17] J. Coron. “High-Order Conversion From Boolean to Arithmetic Masking.” IACR-CHES (2017). https://eprint.iacr.org/2017/252 Sep. 25, 2017. [cited by applicant]
[GaGrMa+20] S. Gao, J. Großschadl, B. Marshall, D. Page, T. Pham, and F. Regazzoni. “An Instruction Set Extension to Support Software-Based Masking.”(2020) https://eprint.iacr.org/2020/773 Jun. 23, 2020. [cited by applicant]
[BeDaPe+10] G. Bertoni, J. Daemen, M. Peeters, and G. Van Assche. ““Building power analysis resistant implementations of Keccak.””SHA-3 Conference (2010) https://keccak.team/files/KeccakDPA.pdf Aug. 2010. [cited by applicant]
[NiRiSc11] S. Nikova, V. Rijmen, and M. Schlaffer. ““Secure Hardware Implementation of Nonlinear Functions in the Presence of Glitches.””J. Cryptol. 24, pp. 292-322 (2011). https://doi.org/10.1007/s00145-010-9085-7 Oct.… [cited by applicant]
[Sa18] M.-J. O. Saarinen. “Arithmetic Coding and Blinding Countermeasures for Lattice Signatures.” J. Cryptogr. Eng. (2018) 8:71-84. http://rdcu.be/oHun https://eprint.iacr.org/2016/276 Jan. 21, 2017. [cited by applicant]
[BaBeEs+18] G. Barthe, S. Belaïd, T. Espitau, P.-A. Fouque, B. Grégoire, M. Rossi, and M. Tibouchi. “Masking the GLP Lattice-Based Signature Scheme at Any Order.”IACR-EUROCRYPT (2018) https://eprint.iacr.org/2018/381 Ap… [cited by applicant]
[BeAnKa+20] M. Van Beirendonck, J. D'Anvers, A. Karmakar, J. Balasch, and I. Verbauwhede.“A Side-Channel Resistant Implementation of SABER.” To appear in ACM JETC (2020). https://eprint.iacr.org/2020/733 Jun. 17, 2020. [cited by applicant]
[BoGoRe+21] J. Bos, M. Gourjon, J. Renes, T. Schneider, and C. van Vredendaal. “Masking Kyber: First- and Higher-Order Implementations.”To appear (2021). https://eprint.iacr.org/2021/483 Apr. 15, 2021. [cited by applicant]
[FrVaRo+21] T. Fritzmann, M. Van Beirendonck, D. Basu Roy, P. Karl, T. Schamberger, I. Verbauwhede, and G. Sigl. “Masked Accelerators and Instruction Set Extensions for Post-Quantum Cryptography.”Preprint (2021). https:… [cited by applicant]
[MiGeTi+19] V. Migliore, B. Gérard, M. Tibouchi, and P. Fouque. “Masking Dilithium: Efficient Implementation and Side-Channel Evaluation.”ACNS (2019). https://eprint.iacr.org/2019/394 Apr. 14, 2019. [cited by applicant]
[RV-ISA] RISC-V International. “RISC-V Specifications.” RISC-V International (2021). https://riscv.org/technical/specifications/. [cited by applicant]
[RV-CRYPTO] RISC-V International (Ben Marshall, Ed.) “RISC-V Cryptography Extension.” RISC-V CETG (2021). https://github.com/riscv/riscv-crypto Feb. 19, 2020. [cited by applicant]
[RV-ZKT] RISC-V International (M.-J. Saarinen, Ed.) “Zkt Constant Time Instruction List.” RISC-V CETG (2021). https://github.com/rvkrypto/riscv-zkt-list Apr. 9, 2021. [cited by applicant]
[RV-VECTOR] “Working draft of the proposed Risc-V V vector extension.”RISC-V (2021). https://github.com/riscv/riscv-v-spec Jun. 13, 2019. [cited by applicant]
[SP 800-185] “SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and ParallelHash”National Institute of Standards and Technology (NIST), Dec. 2016 https://doi.org/10.6028/NIST.SP.800-185 John Kelsey, Shu-Jen Chang, Ray P… [cited by applicant]
[NIST PQC] “Post-Quantum Cryptography: Round 2 Submissions” Jan. 3, 2017 https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Round-2-Submissions. [cited by applicant]
[NIST LWC] “Lightweight Cryptography: Round 1 Candidates” created Jan. 3, 2017 https://csrc.nist.gov/Projects/Lightweight-Cryptography/Round-1-Candidates. [cited by applicant]
[Ascon] Christoph Dobraunig, Maria Eichlseder, Florian Mendel and Martin Schläffer, ““Asconv1.2.”” Proposal to NIST LWC standardization effort, Mar. 2019. https://ascon.iaik.tugraz.at/files/asconv12-nist.pdf https://asc… [cited by applicant]
[Farfalle] Guido Bertoni, Joan Daemen, Seth Hoffert, Michael Peeters, Gilles Van Assche, and Ronny Van Keer, “Farfalle: parallel permutation-based cryptography.” IACR Cryptology ePrintArchive: Report 2016/1188, Dec. 201… [cited by applicant]
[Kangaroo] Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche, Ronny Van Keer, and Benoît Viguier, “KangarooTwelve: fast hashing based on Keccak-p.” Proc. ACNS 2018, LNCS 10892, pp. 400-418, Springer, 2018. … [cited by applicant]
[Keyak] Guido Bertoni, Joan Daemen, Seth Hoffert, Michaël Peeters, Gilles Van Assche, andRonny Van Keer, “Caesar submission: Keyak v2.” Keccak Team, Sep. 2016.https://keccak.team/keyak.html https://keccak.team/files/Key… [cited by applicant]
[RISCV] Andrew Waterman and Krste Asanović (Eds.), “The RISC-V Instruction Set Manual(vols. 1 and 2).” RISC-V Foundation, Jun. 2019. https://riscv.org/specifications/. [cited by applicant]
[Sneik] Markku-Juhani O. Saarinen, “Sneiken and Sneikha: The Sneik Family ofLightweight Cryptographic Algorithms.” Proposal to NIST LWC standardization effort, Mar. 2019. https://github.com/pqshield/sneik. [cited by applicant]
Hayo Baan, Sauvik Bhattacharya, Scott Fluhrer, Oscar Garcia-Morchon, ThijsLaarhoven, Ronald Rietman, Markku-Juhani O. Saarinen, Ludo Tolhuizen, and Zhenfei Zhang. Round5: Compact and fast post-quantum public-keyencrypti… [cited by applicant]
Daniel J. Bernstein. Chacha, a variant of salsa20, 2008. URL: https://cr.yp.to/chacha/chacha-20080128.pdf. Jan. 28, 2008. [cited by applicant]
Joppe W. Bos, Simon Friedberger, Marco Martinoli, Elisabeth Oswald, andMartijn Stam. Fly, you fool! faster frodo for the Arm cortex-m4. IACRCryptology ePrint Archive, 2018:1116, 2018. URL: https://eprint.iacr.org/2018/1… [cited by applicant]
Daniel J. Bernstein et al.: A cross-platformpermutation. In Wieland Fischer and Naofumi Homma, editors, Crypto-graphic Hardware and Embedded Systems—CHES 2017—19th InternationalConference, Taipei, Taiwan, Sep. 25-28, 20… [cited by applicant]
Ray Beaulieu, Douglas Shors, Jason Smith, Stefan Treatman-Clark, BryanWeeks, and Louis Wingers. The Simon and Speck families of lightweightblock ciphers. IACR Cryptology ePrint Archive, 2013:404, 2013. URL: https://epri… [cited by applicant]
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, and Martin Schlaffer.Ascon v1.2. Submission to the Caesar Competition, 2016. URL: https://competitions.cr.yp.to/round3/asconv12.pdf. Sep. 15, 2016. [cited by applicant]
Joan Daemen, Seth Hoffert, Gilles Van Assche, and Ronny Van Keer. Thedesign of xoodoo and xoofff. IACR Trans. Symmetric Cryptol., 2018(4):1-38, 2018. URL: https://doi.org/10.13154/tosc.v2018.i4.1-38, doi:10.13154/tosc.v… [cited by applicant]
Peter Gazi et al. The exact PRF securityof truncation: Tight bounds for keyed sponges and truncated CBC. In Rosario Gennaro and Matthew Robshaw, editors, Advances in Cryptology—Crypto2015—35th Annual Cryptology Conferen… [cited by applicant]
Mike Hamburg. The Strobe protocol framework. IACR Cryptology ePrintArchive, 2017:3, 2017. URL: http://eprint.iacr.org/2017/003. Jan. 3, 2017. [cited by applicant]
Philipp Jovanovic et al. Beyond 2 c/2 security insponge-based authenticated encryption modes. In Palash Sarkar and Tetsulwata, editors, Advances in Cryptology—Asiacrypt 2014—20th Interna-tional Conference on the Theory … [cited by applicant]
Dmitry Khovratovich and Ivica Nikolic. Rotational cryptanalysis of ARX. InSeokhie Hong and Tetsu Iwata, editors, Fast Software Encryption, 17th In-ternational Workshop, FSE 2010, Seoul, Korea, Feb. 7-10, 2010, RevisedSe… [cited by applicant]
Kathleen M. Moriarty, Burt Kaliski, Jakob Jonsson, and Andreas Rusch. PKCS #1: RSA cryptography specifications version 2.2. RFC, 8017:1-78,2016. doi:10.17487/RFC8017. Nov. 2016. [cited by applicant]
Bart Mennink, Reza Reyhanitabar, and Damian Vizár. Security of full-statekeyed sponge and duplex: Applications to authenticated encryption. In Tetsulwata and Jung Hee Cheon, editors, Advances in Cryptology—Asiacrypt2015… [cited by applicant]
B. Poettering. Avraes: The aes block cipher on avr controllers, 2007. URL:http://point-at-infinity.org/avraes/. Mar. 11, 2007. [cited by applicant]
Markku-Juhani O. Saarinen. Beyond modes: Building a secure record protocolfrom a cryptographic sponge permutation. In Benaloh [Ben14], pp. 270-285.doi: 10.1007/978-3-319-04852-9\_14. Feb. 25, 2014. [cited by applicant]
Markku-Juhani O. Saarinen. CBEAM: efficient authenticated encryption fromfeebly one-way ϕ functions. In Benaloh [Ben14], pp. 251-269. doi: 10.1007/978-3-319-04852-9\_13. Nov. 21, 2013. [cited by applicant]
Markku-Juhani O. Saarinen and Billy Bob Brumley. Whirlbob, the whirlpoolbased variant of STRIBOB. In Sonja Buchegger and Mads Dam, editors, Se-cure IT Systems, 20th Nordic Conference, NordSec 2015, Stockholm, Sweden, Oc… [cited by applicant]
Notice of Allowance dated Aug. 5, 2025 for Chinese Patent Application No. 2020800583418. [cited by applicant]
Cited By (1)
US 12,700,987