Skip to content
CY-802 (C) · Lightweight Cryptography/Quick Revision Short Notes

Lightweight Cryptography (CY-802 (C)) - Unit 4 Short Notes

UNIT 4: Lightweight Cryptography

I. Foundations & Motivation

Definition and Need

Lightweight Cryptography designs cryptographic algorithms for resource-constrained environments such as:

  • IoT devices (smart sensors, wearables)

  • RFID tags

  • Wireless Sensor Networks (WSNs)

Primary Constraints:

Constraint Description
Power/Energy Battery-operated, need ultra-low consumption.
Computational Speed Limited CPU cycles (often 8/16-bit).
Memory (RAM/ROM) Very small volatile/non-volatile storage (KBytes).
Hardware Area Minimal gate count (GE) for ASIC/FPGA.
Cost Must be extremely low per unit.

Why Traditional Cryptography (AES, RSA, SHA-2) is Unsuitable

  1. High Computational/Energy Cost: AES-128 requires ~1000-2000 GE; RSA operations are prohibitively expensive.

  2. Large Memory Footprint: AES-128 code size ~3-10 KB; large lookup tables (S-Boxes) exceed ROM.

  3. Unsuitable Hardware Characteristics: Not optimized for bit-level operations or minimal gate count.

Key Evaluation Metrics

  • Gate Equivalents (GE): Hardware area measure.

  • RAM/ROM Usage: Bytes of memory.

  • Energy Consumption: Picojoules per bit (pJ/bit).

  • Throughput: Bits per second (bps) at a given area/power.

  • Latency: Time for one encryption/operation.

  • "Operation": A basic computational step (e.g., one S-Box lookup, one round, one permutation layer).

[!TIP] Exam Focus: Be ready to define "operation" in the context of a specific cipher's round function.


II. Lightweight Block Ciphers: Design & Examples

Core Design Strategies

Strategy ARX (Add-Rotate-XOR) SPN (Substitution-Permutation) Feistel
Hardware Moderate GE, no S-Boxes Can be minimal with small S-Boxes Often larger due to round function duplication
Software Very efficient on 32/64-bit Can be slow if small S-Boxes Good for small block sizes
Examples SPECK, SIMON PRESENT, GIFT CLEFIA, DESL

Component Optimization:

  • S-Box: Small (4-bit or 8-bit), hardware-friendly (bit-sliced), or software-optimized (lookup table). Trade-off: Security vs. Size.

  • Permutation/Layer: Simple linear layer (bit permutation, lightweight MDS matrix) for diffusion at minimal cost.

  • Key Schedule: Lightweight (simple, low memory) vs. Secure (resists related-key attacks). Often a major trade-off point.

  • Round Function: Minimize operations per round (e.g., single S-Box layer, simple linear layer).

  • Parameters: Often smaller block size (64-bit) and key size (80/128-bit).

Analysis of Specific Cipher Families

1. PRESENT

  • Structure: SPN.

  • Parameters: 64-bit block, 80/128-bit key, 31 rounds.

  • Components:

    • 4-bit S-Box (optimized for hardware).

    • Bit permutation layer (simple wiring).

    • Key schedule: 31 round keys generated from master key.

  • Design Philosophy: Extreme hardware minimalism (target ~1000 GE). Sacrifices some speed/software efficiency.

2. CLEFIA

  • Structure: Feistel-like (type-2 Feistel network).

  • Parameters: 128-bit block, 128/192/256-bit key, 18/22/26 rounds.

  • Components:

    • Two 8-bit S-Boxes (software-friendly for 8-bit CPUs).

    • Flexible key schedule with two F-functions.

  • Design Philosophy: Software efficiency on 8-bit microcontrollers while maintaining security.

3. DESL / DESXL

  • Philosophy: Reuse and optimize existing, well-analyzed components (DES S-Boxes).

  • DESL: Uses a single 8-bit S-Box repeatedly in each round to reduce hardware area.

  • DESXL: Uses modified S-Boxes and a more secure key schedule than DESL.

  • Goal: Leverage years of cryptanalysis on DES core while achieving lightweight implementation.

Modes of Operation for Lightweight Block Ciphers

  • Purpose: Extend block cipher to encrypt data > block size.

  • Preferred Mode: CTR (Counter) Mode.

    • Why: Parallelizable (low latency), random access, no propagation delay.

    • Implementation: Ciphertext = Plaintext ⊕ Encrypt(IV || Counter).

    • Example: PRESENT-CTR. Critical: Secure nonce/IV management on constrained devices (no space for large counters).

  • Avoid: ECB (insecure), CBC (sequential, higher latency).

Role of Open Design and Public Cryptanalysis

  • Importance: Public scrutiny is essential for discovering flaws and building trust. "Security through obscurity" fails.

  • History: Many lightweight ciphers have been broken (e.g., related-key attacks on SIMON/SPECK, meet-in-the-middle on PRESENT variants).

  • Design Balance: Simplicity aids analysis but may reduce security margin. Need sufficient security margin (extra rounds beyond the minimum required).

  • Case Study: SIMON/SPECK (NSA) faced intense public cryptanalysis leading to adjustments and debate over their design process.

[!TIP] Common Pitfall: Confusing the structure (SPN vs. Feistel) with the mode of operation (CTR, CBC). Structure is internal to the cipher; mode is how it's used.


III. Lightweight Key Management

Fundamental Concepts

Key management lifecycle: Generation → Distribution → Storage → Rotation → Revocation → Destruction.

  • Challenge in Constrained Devices: Secure storage (limited EEPROM/Flash), true random number generation (TRNG) quality, scalability for millions of devices.

Centralized vs. Distributed Approaches

Aspect Centralized (KDC) Distributed (Pairwise/Group)
Mechanism Trusted third party (KDC) shares a key with each node. Nodes request session keys from KDC. Nodes establish keys directly (e.g., via pre-distributed key matrix, or lightweight asymmetric).
Pros Simple for devices, single policy point, easy revocation. No single point of failure, better scalability, lower communication overhead for node-to-node.
Cons Single point of failure/attack, scalability bottleneck (KDC load), all traffic passes through KDC. Complex key establishment, high initial overhead, difficult revocation, vulnerable to node capture (reveals multiple keys).
Security Trust model hinges on KDC security. Resilience depends on capture resistance of individual nodes.

Integration with Standard Protocols (IPSec, TLS)

  • Challenges: Handshake overhead (RSA/ECDH certificates are large), session resumption cost.

  • Lightweight Adaptations:

    • Pre-Shared Key (PSK) Mode: Bypass expensive handshake. Use a pre-shared symmetric key.

    • Session Resumption: Use lightweight session tickets (encrypted with a group key).

    • Cipher Suite Selection: Negotiate lightweight ciphers (e.g., PRESENT, CLEFIA) and hash (e.g., PHOTON) in the record layer.

    • Elliptic Curves: Use efficient curves like Curve25519 for ECDH if asymmetric is needed.

Lightweight Group Key Management for IoT Key Evaluation Considerations for a New Protocol:

  1. Scalability: How does communication overhead grow with group size N? (e.g., O(N) vs O(log N)).

  2. Rekeying Efficiency: Cost to change group key (forward/backward secrecy). Message count and size.

  3. Resilience to Node Capture: How many keys are compromised if one node is captured?

  4. Communication Overhead: Number of messages and total bytes transmitted per join/leave.

  5. Computational Cost: Operations required on the constrained device (e.g., encryptions, MACs).

  6. Dynamic Membership: Support for efficient joins and leaves.

Integration of Symmetric Key Management

  • Use a centralized group manager (like a KDC but for groups).

  • Manager encrypts the new group key with each member's individual symmetric key (from a pre-distribution or prior pairwise key).

  • Logical Key Hierarchy (LKH): Adapt LKH tree where each node stores keys for its path. Rekeying only affects nodes on affected path (O(log N) messages). Requires secure key storage per node.

  • Example: A gateway (manager) holds a group key KG. When a node joins, manager sends KG encrypted with that node's unique key Ki.


IV. Other Lightweight Primitives & Considerations

Lightweight Cryptographic Hash Functions

  • Purpose: Integrity, HMAC, digital signatures (with asymmetric), commitment schemes.

  • Design Strategies:

    • Reduced rounds (e.g., PHOTON-256/32).

    • Smaller internal state (e.g., 256-bit vs. 512-bit).

    • Lightweight S-Boxes and permutations.

  • Examples & Applications:

    • PHOTON: Sponge-based, used in RFID authentication.

    • SPONGENT: Ultra-lightweight for RFID.

    • QUARK: For embedded systems.

    • Application: Lightweight HMAC for securing IoT MQTT/CoAP messages.

Lightweight Stream Ciphers

  • Design: Small internal state (n bits), efficient update function (LFSR, NLFSR, asynchronous).

  • Vulnerability: Birthday Attack & State Collisions

    • Principle: After generating ~$$\displaystyle 2^{n/2} $$ output bits, two different internal states are likely to produce the same output sequence (collision) due to the birthday paradox.

    • Consequence: Attacker can recover the key/state by identifying collisions.

    • Design Optimization: Ensure state size n ≥ 128 bits for long-term security. Or, design the cipher to refresh state from key/IV periodically to limit output per state.

  • Examples: Trivium (eSTREAM), Grain (eSTREAM), MICKEY.

Symmetric vs. Asymmetric Cryptography

Feature Symmetric Asymmetric (Lightweight ECC)
Key Same secret key for encryption/decryption. Public key / Private key pair.
Speed Very fast (hardware/software). 100-1000x slower than symmetric.
Use Case Bulk data encryption, MACs. Initial key exchange, digital signatures.
Lightweight Choice PRESENT, CLEFIA, LEA, CHAM. Elliptic Curve Cryptography (ECC) with small curves (e.g., Curve25519, NIST P-256).

Security Threats Specific to Tiny Devices

  1. Physical Attacks:

    • Side-Channel: Power analysis (SPA/DPA), timing attacks, electromagnetic (EM) analysis.

    • Fault Injection: Laser/voltage glitch to induce errors and reveal secrets.

    • Micro-probing: Physical access to chip internals.

  2. Software Attacks: Memory corruption, code reuse attacks (ROP), buffer overflows in firmware.

  3. Network Attacks: Replay, DoS (exhaust battery), but impact is amplified due to limited resources.

  4. Supply Chain & Cloning: Devices can be cloned if unique keys are not securely injected.

[!TIP] Exam Winner: Always link a threat to the constraint it exploits (e.g., side-channel → low power makes measurements easier; DoS → limited battery).


BOXED: Critical Formulas & Definitions

  • Birthday Bound for Stream Ciphers: For an n-bit internal state, state collisions become probable after generating approximately $$\displaystyle \boxed{2^{n/2}} $$ output bits.

  • Definition of "Operation": In lightweight cipher evaluation, an "operation" refers to a fundamental computational step of the algorithm, such as a single S-Box substitution, one round of the cipher, or one application of the linear diffusion layer.

  • CTR Mode Encryption:

$$C_i = P_i \oplus E_K(IV \parallel \text{Counter}_i)$$

  • Key Management Core Challenge: Securely establishing and maintaining secret keys on devices with limited secure storage and computational capacity.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in