IP Library Granted Patent US 12,474,891
Granted Patent B2
US 12,474,891 · App. 17/576,299 · Granted Nov 18, 2025

Cryptographic architecture for cryptographic permutation

Inventor: Markku-Juhani Olavi Saarinen (Oxford, GB)
Assignee: PQShield Ltd
G06F7/584G06F7/768G06F9/30029G06F9/30032G06F21/602G06F21/72H04L9/0631H04L9/0643H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,474,891
App. No.
17/576,299
Granted
Nov 18, 2025
Kind
B2
Abstract

Cryptographic methods and systems are described. Certain examples relate to performing cryptographic operations that involve a cryptographic permutation. The methods and systems may be used to provide cryptographic functions such as hashing, encryption, decryption and random number generation. In one example, a cryptographic architecture is provided. The cryptographic architecture has a processor interface comprising a set of cryptographic registers, where the processor interface is accessible by at least one processing unit. The cryptographic architecture also has a cryptographic permutation unit comprising circuitry to perform a cryptographic permutation using data stored within the set of cryptographic registers. In examples, the at least one processing unit instructs the cryptographic permutation and accesses a result of the cryptographic permutation using the processor interface.

Claims (52)

1 . A cryptographic architecture comprising:

a processor interface comprising a set of cryptographic registers, the processor interface being accessible by at least one processing unit, the at least one processing unit being separate from the cryptographic architecture; and

cryptographic permutation circuitry configured to perform a cryptographic permutation using data stored within the set of cryptographic registers,

wherein the at least one processing unit instructs the cryptographic architecture to perform the cryptographic permutation and accesses a result of the cryptographic permutation using the processor interface,

wherein the set of cryptographic registers comprise:

one or more control registers that are accessible to the at least one processing unit;

a permutation state register to store a permutation state;

a permutation input register to store permutation input data, the permutation input register being writable by the at least one processing unit;

a permutation output register to store output data, the permutation output register being readable by the at least one processing unit, wherein the permutation state is not visible to the at least one processing unit;

a mask input register to store an input mask, the mask input register being writable by the at least one processing unit;

permutation masking circuitry, communicatively coupled to the mask input register and the permutation state register, to apply an AND operation to data derived from the input mask and data derived from permutation data from the permutation state register; and

input application circuitry, communicatively coupled to the permutation masking circuitry and the permutation input register, to apply an XOR operation to data derived from the permutation masking circuitry and data derived from the permutation input data, the input application circuitry being configured to supply output data to the cryptographic permutation circuitry;

wherein the cryptographic architecture is configured to indicate a completion of the cryptographic permutation by setting a control flag within the control registers.

2 . The cryptographic architecture of claim 1 , wherein the cryptographic architecture is configured to perform the cryptographic permutation based on a single machine code instruction that is executed by the at least one processing unit.

3 . The cryptographic architecture of claim 2 , wherein the single machine code instruction is implemented as an Instruction Set Architecture (ISA) extension.

4 . The cryptographic architecture of claim 1 , wherein the processor interface comprises a plurality of registers configured to store at least b-bits, where b is a size in bits of a permutation input.

5 . The cryptographic architecture of claim 1 , wherein the cryptographic permutation circuitry is configured to perform a KECCAK-p permutation.

6 . The cryptographic architecture of claim 1 , wherein the cryptographic permutation circuitry is configured to perform a keyless permutation comprising a plurality of rounds.

7 . The cryptographic architecture of claim 1 , wherein the at least one processing unit is able to use the cryptographic architecture to perform one or more of the following:

an absorb cryptographic operation to mix input data with a permutation state;

a squeeze cryptographic operation to obtain an output using the permutation state;

an encrypt cryptographic operation to encrypt input data using the permutation state; and

a decrypt cryptographic operation to decrypt input data using the permutation state.

8 . The cryptographic architecture of claim 1 , comprising:

input XOR circuitry to apply an input XOR operation, the input XOR operation being applied to data derived from the permutation input data in the permutation input register and data derived from the permutation state in the permutation state register,

wherein the input XOR circuitry is communicatively coupled to an XOR output register to store an output of the input XOR circuitry.

9 . The cryptographic architecture of claim 1 , wherein, following performance of the cryptographic permutation by the cryptographic permutation circuitry, an output of the cryptographic permutation circuitry is copied to the permutation state register.

10 . The cryptographic architecture of claim 1 , wherein the one or more control registers comprise one or more of:

an identifier register, writable by the at least one processing unit, to store an identifier of a cryptographic operation to be performed;

a start register, writable by the at least one processing unit, to store a start flag for the cryptographic operation;

a ready register, readable by the at least one processing unit, to store a ready flag indicating that the cryptographic architecture is ready to start another cryptographic operation;

one or more round registers, writable by the at least one processing unit, to store one or more flags relating to rounds of cryptographic permutation; and

an interrupt control register, writable by the at least one processing unit, to control interrupts to the at least one processing unit.

11 . The cryptographic architecture of claim 1 , wherein the cryptographic architecture is useable by the at least one processing unit to perform a cryptographic permutation for a SHA-3 function.

12 . A method of performing a cryptographic operation comprising:

receiving, at a cryptographic architecture, an instruction to perform the cryptographic operation from a processing unit, the processing unit being separate from the cryptographic architecture, the cryptographic architecture comprising a set of cryptographic registers comprising one or more control registers that are accessible to the at least one processing unit, wherein receiving said instruction comprises:

accessing a control register of the cryptographic architecture to determine whether a start flag has been set by the processing unit to indicate a start of the cryptographic operation;

loading, by a cryptographic permutation circuitry of the cryptographic architecture, a permutation state from a permutation state register;

loading, by the cryptographic permutation circuitry, permutation input data from a permutation input register, the permutation input data being written under the control of the processing unit;

loading, by the cryptographic permutation circuitry, mask input data from a mask input register;

updating, by the cryptographic architecture, the permutation state in the permutation state register of the set of cryptographic registers by performing an XOR operation as a function of the permutation input data and a result of an AND operation performed on the mask input data and the permutation state to generate updated data;

performing, using the cryptographic permutation circuitry, a cryptographic permutation on the updated data;

storing, by the cryptographic architecture, an output of the cryptographic permutation into the permutation state register; and

indicating, by the cryptographic architecture, to the at least one processing unit that the permutation is complete, wherein the processing unit accesses the output of the cryptographic permutation from the set of cryptographic registers, said indicating comprising setting a control flag within the control registers.

13 . The method of claim 12 , comprising:

reading, by the processing unit, the output of the cryptographic permutation from the set of cryptographic registers.

14 . The method of claim 12 , comprising:

loading, by the cryptographic permutation circuitry from a round control register, a round count;

using, by the cryptographic permutation circuitry, the round count in the cryptographic permutation; and

incrementing the round count in the round control register,

wherein the loading, using and incrementing operations are repeated based on a comparison of the round control register and an end control register.

15 . The cryptographic architecture of claim 1 , wherein the set of cryptographic registers are memory mapped to the address space of the at least one processing unit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2022
From: SAARINEN, MARKKU-JUHANI OLAVI
To: PQSHIELD LTD.
Reel/Frame 058662/0889 →
Priority Claims (1)
GB 1910372 · Jul 19, 2019 · national
Continuity (2)
Continuation PCTGB2020051699 · Jul 15, 2020
Related Publication 20220138349A1 · May 5, 2022
References Cited (145)
US 3911330A · Fletcher et al. · 1975 [cited by applicant]
US 4589120A · Mendala · 1986 [cited by examiner]
US 5764765A · Phoenix · 1998 [cited by applicant]
US 6407766B1 · Ramanujan · 2002 [cited by applicant]
US 6748083B2 · Hughes · 2004 [cited by applicant]
US 7437081B2 · Howell · 2008 [cited by applicant]
US 8194855B2 · Shantz et al. · 2012 [cited by applicant]
US 8538012B2 · Dixon et al. · 2013 [cited by applicant]
US 8572410B1 · Tkacik · 2013 [cited by examiner]
US 8761401B2 · Sprunk · 2014 [cited by applicant]
US 8782774B1 · Pahl · 2014 [cited by applicant]
US 8855316B2 · Wiseman · 2014 [cited by applicant]
US 9628268B2 · Kiang · 2017 [cited by applicant]
US 9772845B2 · Yap et al. · 2017 [cited by applicant]
US 9960465B2 · Dudley · 2018 [cited by applicant]
US 10038550B2 · Gopal et al. · 2018 [cited by applicant]
US 10057058B2 · Murakami · 2018 [cited by applicant]
US 10313129B2 · Gopal · 2019 [cited by examiner]
US 20020040429A1 · Dowling · 2002 [cited by applicant]
US 20030084309A1 · Khon · 2003 [cited by applicant]
US 20050138352A1 · Gauvreau · 2005 [cited by applicant]
US 20070065154A1 · Luo · 2007 [cited by applicant]
US 20070076884A1 · Wellbrock · 2007 [cited by applicant]
US 20070195774A1 · Sherman · 2007 [cited by applicant]
US 20080019524A1 · Kim et al. · 2008 [cited by applicant]
US 20080056488A1 · Motoyama · 2008 [cited by examiner]
US 20080229116A1 · Dixon et al. · 2008 [cited by applicant]
US 20080298583A1 · Ahmed · 2008 [cited by examiner]
US 20090254718A1 · Biscondi et al. · 2009 [cited by applicant]
US 20100115237A1 · Brewer et al. · 2010 [cited by applicant]
US 20100128872A1 · Cordery et al. · 2010 [cited by applicant]
US 20100146296A1 · Kim et al. · 2010 [cited by applicant]
US 20100195820A1 · Frank · 2010 [cited by examiner]
US 20100235417A1 · Baek · 2010 [cited by applicant]
US 20100289943A1 · Tokoro · 2010 [cited by examiner]
US 20110206204A1 · Sychev · 2011 [cited by applicant]
US 20110213979A1 · Wiseman · 2011 [cited by applicant]
US 20120076293A1 · Smith et al. · 2012 [cited by applicant]
US 20130275722A1 · Yap et al. · 2013 [cited by applicant]
US 20140010234A1 · Patel · 2014 [cited by applicant]
US 20140068765A1 · Choi · 2014 [cited by applicant]
US 20140095844A1 · Gopal et al. · 2014 [cited by applicant]
US 20140133652A1 · Oshida · 2014 [cited by applicant]
US 20140189369A1 · Woolrich et al. · 2014 [cited by applicant]
US 20140254792A1 · Gammel · 2014 [cited by applicant]
US 20150149788A1 · Gupta · 2015 [cited by examiner]
US 20160080143A1 · Kindarji et al. · 2016 [cited by applicant]
US 20160241396A1 · Fu · 2016 [cited by applicant]
US 20160359626A1 · Fu · 2016 [cited by applicant]
US 20160366094A1 · Mason · 2016 [cited by applicant]
US 20170109162A1 · Yap et al. · 2017 [cited by applicant]
US 20170142081A1 · Jutla · 2017 [cited by examiner]
US 20170180131A1 · Ghosh · 2017 [cited by examiner]
US 20170214525A1 · Zhao · 2017 [cited by applicant]
US 20170230173A1 · Choi · 2017 [cited by applicant]
US 20170242590A1 · Gokhale · 2017 [cited by examiner]
US 20180063100A1 · Peeters et al. · 2018 [cited by applicant]
US 20180157489A1 · Yap · 2018 [cited by examiner]
US 20180176091A1 · Yoon · 2018 [cited by applicant]
US 20180212761A1 · Bilgin et al. · 2018 [cited by applicant]
US 20190036821A1 · Levy · 2019 [cited by applicant]
US 20190109703A1 · Gueron et al. · 2019 [cited by applicant]
US 20190146700A1 · Gschwind · 2019 [cited by examiner]
US 20190349392A1 · Wetterwald · 2019 [cited by applicant]
US 20200084222A1 · William · 2020 [cited by applicant]
CN 103812643A · 2014 [cited by applicant]
CN 107800532A · 2018 [cited by applicant]
EP 0801477A1 · 1997 [cited by examiner]
EP 0955590A1 · 1999 [cited by examiner]
EP 0992887A2 · 2000 [cited by examiner]
EP 1068565A2 · 2001 [cited by applicant]
JP H03251890A · 1991 [cited by applicant]
JP H0697930A · 1994 [cited by applicant]
JP 20010195555A · 2001 [cited by applicant]
JP 2002107691A · 2002 [cited by applicant]
JP 20050532604A · 2005 [cited by applicant]
JP 2008233683A · 2008 [cited by applicant]
JP 2014197169A · 2014 [cited by applicant]
JP 2015014962A · 2015 [cited by applicant]
JP H1031530A · 2019 [cited by applicant]
JP 20190511791A · 2019 [cited by applicant]
KR 1020190020988A · 2019 [cited by applicant]
WO 0176129A2 · 2001 [cited by applicant]
WO 03021863A1 · 2003 [cited by applicant]
WO 2011123575A1 · 2011 [cited by applicant]
WO 2014136594A1 · 2014 [cited by applicant]
WO WO2019158641A1 · 2019 [cited by examiner]
Liang , W. and Long Jing: “A cryptographic algorithm based on Linear Feedback Shift Register.” 2010 International Conference on Computer Application and System Modeling (ICCASM 2010). vol. 15. IEEE, 2010. (Year: 2010). [cited by applicant]
International Search Report and Written Opinion dated Nov. 7, 2022 for PCT Application No. PCT/GB2022/051829. [cited by applicant]
Peter Schwabe and Ko Stoffelen. All the AES you need on cortex-m3 and M4.In Roberto Avanzi and Howard M. Heys, editors, Selected Areas in Cryptog-raphy—SAC 2016—23rd International Conference, St. John's, NL, Canada,Aug.… [cited by applicant]
Ascon Lightweight Authenticated Encryption and Hashing, Jan. 2, 2019. [cited by applicant]
David J. Wheeler and Roger M. Needham. Correction to xtea. InformalManuscript or Report, 1998. URL: https://www.mjos.fi/doc/misc/xxtea.pdf. Oct. 1998. [cited by applicant]
“Blitter Hardware” of the Amiga Hardware Reference Manual. Addison-Wesley. 1985, Chapter 6. [cited by applicant]
““Crypto-processeur””, pp. 1-190 URL: https://tel.archives-ouvertes.fr/tel-00978472/document sections 3 and 4, 2012. [cited by applicant]
[CC-PP-0084] “Security IC Platform Protection Profile with Augmentation Packages.” Bundesamt für Sicherheit in der Informationstechnik (BSI) reference BSI-CC-PP-0084-2014.https://www.commoncriteriaportal.org/files/ppfil… [cited by applicant]
[Sogis-Ava] “Application of Attack Potential to Smartcards and Similar Devices.” Version 3.1. (2020). https://www.sogis.eu/documents/cc/domains/sc/JIL-Application-of-Attack-Potential-to-Smartcards-v3-1.pdf Jun. 2020. [cited by applicant]
[SP800-193] “Platform Firmware Resiliency Guidelines.” NIST SP 800-193. (2018). DOI: https://doi.org/10.6028/NIST.SP.800-193 May 2018. [cited by applicant]
[RFC8391] “XMSS: extended Merkle Signature Scheme.” IETF RFC 8391 (2018). DOI: https://doi.org/10.17487/RFC8391 May 2018. [cited by applicant]
[RFC8554] “Leighton-Micali Hash-Based Signatures.” IETF RFC 8554 (2018). DOI: https://doi.org/10.17487/RFC8554, Apr. 2018. [cited by applicant]
[FIPS202] “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions.” FIPS Pub 202. (2015). DOI: https://doi.org/10.6028/NIST.FIPS.202 Aug. 2015. [cited by applicant]
[PQFAQ] ““Post-Quantum Cryptography FAQs / Transition and Migration.”” https://csrc.nist.gov/projects/post-quantum-cryptography/faqs Jan. 3, 2017. [cited by applicant]
[CoGrVa14] J. Coron, J. Großschadl, P. K. Vadnala. ““Secure Conversion Between Boolean and Arithmetic Masking of Any Order.”” IACR-CHES (2014). http://www.crypto-uni.lu/jscoron/publications/secconvorder.pdf Sep. 23, 201… [cited by applicant]
[Co17] J. Coron. “High-Order Conversion From Boolean to Arithmetic Masking.” IACR-CHES (2017). https://eprint.iacr.org/2017/252 Sep. 25, 2017. [cited by applicant]
[GaGrMa+20] S. Gao, J. Großschädl, B. Marshall, D. Page, T. Pham, and F. Regazzoni.“An Instruction Set Extension o Support Software-Based Masking.” (2020) https://eprint.iacr.org/2020/773 Jun. 23, 2020. [cited by applicant]
[BeDaPe+10] G. Bertoni, J. Daemen, M. Peeters, and G. Van Assche. ““Building power analysis resistant Implementations of Keccak.”” SHA-3 Conference (2010) https://keccak.team/files/KeccakDPA.pdf Aug. 2010. [cited by applicant]
[NiRiSc11] S. Nikova, V. Rijmen, and M. Schlaffer. ““Secure Hardware Implementation of Nonlinear Functions in the Presence of Glitches.”” J. Cryptol. 24, pp. 292-322 (2011). https://doi.org/10.1007/s00145-010-9085-7 Oct… [cited by applicant]
[Sa18] M.-J. O. Saarinen. “Arithmetic Coding and Blinding Countermeasures for Lattice Signatures.” J. Cryptogr. Eng. (2018) 8:71-84. http://rdcu.be/oHun https://eprint.iacr.org/2016/276 Jan. 21, 2017. [cited by applicant]
[BaBeEs+18] G. Barthe, S. Belaïd, T. Espitau, P.-A. Fouque, B. Grégoire, M. Rossi, and M. Tibouchi. “Masking the GLP Lattice-Based Signature Scheme at Any Order.” IACR-Eurocrypt (2018) https://eprint.iacr.org/2018/381 A… [cited by applicant]
[BeAnKa+20] M. Van Beirendonck, J. D'Anvers, A. Karmakar, J. Balasch, and I. Verbauwhede.“A Side-Channel Resistant Implementation of Saber.” To appear in ACM JETC (2020). https://eprint.iacr.org/2020/733 Jun. 17, 2020. [cited by applicant]
[BoGoRe+21] J. Bos, M. Gourjon, J. Renes, T. Schneider, and C. van Vredendaal. “Masking Kyber: First- and Higher-Order Implementations.” To appear (2021). https://eprint.iacr.org/2021/483 Apr. 15, 2021. [cited by applicant]
[FrVaRo+21] T. Fritzmann, M. Van Beirendonck, D. Basu Roy, P. Karl, T. Schamberger, I. Verbauwhede, and G. Sigl. “Masked Accelerators and Instruction Set Extensions for Post-Quantum Cryptography.” Preprint (2021). https… [cited by applicant]
[MiGeTi+19] V. Migliore, B. Gérard, M. Tibouchi, and P. Fouque. “Masking Dilithium: Efficient Implementation and Side-Channel Evaluation.” ACNS (2019). https://eprint.iacr.org/2019/394 Apr. 14, 2019. [cited by applicant]
[RV-ISA] RISC-V International. “RISC-V Specifications.” RISC-V International (2021). https://riscv.org/technical/specifications/. [cited by applicant]
[RV-Crypto] RISC-V International (Ben Marshall, Ed.) “RISC-V Cryptography Extension.” RISC-V CETG (2021). https://github.com/riscv/riscv-crypto Feb. 19, 2020. [cited by applicant]
[RV-ZKT] RISC-V International (M.-J. Saarinen, Ed.) “ZKT Constant Time Instruction List.” RISC-V CTEG (2021). https://github.com/rvkrypto/riscv-zkt-list Apr. 9, 2021. [cited by applicant]
[RV-Vector] Working draft of the proposed RISC-V V vector extension. RISC-V (2021). https://github.com/riscv/riscv-v-spec Jun. 13, 2019. [cited by applicant]
[SP 800-185] “SHA-3 Derived Functions: cShake, KMAC, TupleHash, and ParallelHash” National Institute of Standards and Technology (NIST), Dec. 2016 https://doi.org/10.6028/NIST.SP.800-185 John Kelsey, Shu-Jen Chang, Ray … [cited by applicant]
[NIST PQC] “Post-Quantum Cryptography: Round 2 Submissions” Jan. 3, 2017 https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Round-2-Submissions. [cited by applicant]
[NIST LWC] “Lightweight Cryptography: Round 1 Candidates” created Jan. 3, 2017 https://csrc.nist.gov/Projects/Lightweight-Cryptography/Round-1-Candidates. [cited by applicant]
[ASCON] Christoph Dobraunig, Maria Eichlseder, Florian Mendel and Martin Schlaffer, ““Asconv1.2.”” Proposal to NIST LWC standardization effort, Mar. 2019. https://ascon.iaik.tugraz.at/files/asconv12-nist.pdf https://asc… [cited by applicant]
[Farfalle] Guido Bertoni, Joan Daemen, Seth Hoffert, Michaël Peeters, Gilles Van Assche, and Ronny Van Keer, “Farfalle: parallel permutation-based cryptography.” IACR Cryptology ePrintArchive: Report 2016/1188, Dec. 201… [cited by applicant]
[Kangaroo] Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche, Ronny Van Keer, and Benoît Viguier, “KangarooTwelve: fast hashing based on Keccak-p.” Proc. ACNS 2018,LNCS 10892, pp. 400-418, Springer, 2018. h… [cited by applicant]
[Keyak] Guido Bertoni, Joan Daemen, Seth Hoffert, Michael Peeters, Gilles Van Assche, andRonny Van Keer, “Caesar submission: Keyak v2.” Keccak Team, Sep. 2016.https://keccak.team/keyak.html https://keccak.team/files/Key… [cited by applicant]
[RISCV] Andrew Waterman and Krste Asanović (Eds.), “The RISC-V Instruction Set Manual(vols. 1 and 2).” RISC-V Foundation, Jun. 2019. https://riscv.org/specifications/. [cited by applicant]
[Sneik] Markku-Juhani O. Saarinen, “Sneiken and Sneikha: The Sneik Family of Lightweight Cryptographic Algorithms.” Proposal to NIST LWC standardization effort, Mar. 2019. https://github.com/pqshield/sneik. [cited by applicant]
Hayo Baan, Sauvik Bhattacharya, Scott Fluhrer, Oscar Garcia-Morchon, ThijsLaarhoven, Ronald Rietman, Markku-Juhani O. Saarinen, Ludo Tolhuizen,and Zhenfei Zhang. Round5: Compact and fast post-quantum public-keyencryptio… [cited by applicant]
Daniel J. Bernstein. Chacha, a variant of salsa20, 2008. URL: https://cr.yp.to/chacha/chacha-20080128.pdf. Jan. 28, 2008. [cited by applicant]
Joppe W. Bos, Simon Friedberger, Marco Martinoli, Elisabeth Oswald, andMartijn Stam. Fly, you fool! faster frodo for the ARM cortex-m4. IACRCryptology ePrint Archive, 2018:1116, 2018. URL: https://eprint.iacr.org/2018/1… [cited by applicant]
Daniel J. Bernstein et al : A cross-platformpermutation. In Wieland Fischer and Naofumi Homma, editors, Crypto-graphic Hardware and Embedded Systems—Ches 2017—19th InternationalConference, Taipei, Taiwan, Sep. 25-28, 20… [cited by applicant]
Ray Beaulieu, Douglas Shors, Jason Smith, Stefan Treatman-Clark, BryanWeeks, and Louis Wingers. The Simon and Speck families of lightweightblock ciphers. IACR Cryptology ePrint Archive, 2013:404, 2013. URL: https://epri… [cited by applicant]
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, and Martin Schläffer.Ascon v1.2. Submission to the Caesar Competition, 2016. URL: https://competitions.cr.yp.to/round3/asconv12.pdf. Sep. 15, 2016. [cited by applicant]
Joan Daemen, Seth Hoffert, Gilles Van Assche, and Ronny Van Keer. Thedesign of xoodoo and xoofff. IACR Trans. Symmetric Cryptol., 2018(4):1-38, 2018. URL: https://doi.org/10.13154/tosc.v2018.i4.1-38, doi:10.13154/tosc.v… [cited by applicant]
Peter Gazi et al. The exact PRF security of truncation: Tight bounds for keyed sponges and truncated CBC. In Rosario Gennaro and Matthew Robshaw, editors, Advances in Cryptology—CRYPTO2015—35th Annual Cryptology Confere… [cited by applicant]
Mike Hamburg. The Strobe protocol framework. IACR Cryptology ePrintArchive, 2017:3, 2017. URL: http://eprint.iacr.org/2017/003. Jan. 3, 2017. [cited by applicant]
Philipp Jovanovic et al. Beyond 2 c/2 security insponge-based authenticated encryption modes. In Palash Sarkar and Tetsulwata, editors, Advances in Cryptology—Asiacrypt 2014—20th Interna-tional Conference on the Theory … [cited by applicant]
Dmitry Khovratovich and Ivica Nikolic. Rotational cryptanalysis of ARX. InSeokhie Hong and Tetsu Iwata, editors, Fast Software Encryption, 17th In-ternational Workshop, FSE 2010, Seoul, Korea, Feb. 7-10, 2010, RevisedSe… [cited by applicant]
Kathleen M. Moriarty, Burt Kaliski, Jakob Jonsson, and Andreas Rusch.PKCS #1: RSA cryptography specifications version 2.2. RFC, 8017:1-78,2016. doi:10.17487/RFC8017. Nov. 2016. [cited by applicant]
Bart Mennink, Reza Reyhanitabar, and Damian Vizár. Security of full-statekeyed sponge and duplex: Applications to authenticated encryption. In Tetsulwata and Jung Hee Cheon, editors, Advances in Cryptology—Asiacrypt2015… [cited by applicant]
B. Poettering. Avraes: The aes block cipher on avr controllers, 2007. URL:http://point-at-infinity.org/avraes/. Mar. 11, 2007. [cited by applicant]
Markku-Juhani O. Saarinen. Beyond modes: Building a secure record protocol from a cryptographic sponge permutation. In Benaloh [Ben14], pp. 270-285.doi:10.1007/978-3-319-04852-9\_14. Feb. 25, 2014. [cited by applicant]
Markku-Juhani O. Saarinen. CBeam: efficient authenticated encryption fromfeebly one-way ϕ functions. In Benaloh [Ben14], pp. 251-269. doi:10.1007/978-3-319-04852-9\_13. Nov. 21, 2013. [cited by applicant]
Markku-Juhani O. Saarinen and Billy Bob Brumley. Whirlbob, the whirlpoolbased variant of Stribob. In Sonja Buchegger and Mads Dam, editors, Se-cure IT Systems, 20th Nordic Conference, NordSec 2015, Stockholm, Sweden, Oc… [cited by applicant]
Japanese Office Action dated Jul. 1, 2024 for Japanese Patent Application No. 2022-503796. [cited by applicant]
Notice of Allowance dated Aug. 5, 2025 for Chinese Patent Application No. 2020800583418. [cited by applicant]
Notice of Allowance dated Jun. 30, 2025 for U.S. Appl. No. 18/412,267. [cited by applicant]