UNIT 4: Lightweight Cryptography
I. Foundations & Motivation
Definition and Need
Lightweight Cryptography designs cryptographic algorithms for resource-constrained environments such as:
-
IoT devices (smart sensors, wearables)
-
RFID tags
-
Wireless Sensor Networks (WSNs)
Primary Constraints:
| Constraint | Description |
|---|---|
| Power/Energy | Battery-operated, need ultra-low consumption. |
| Computational Speed | Limited CPU cycles (often 8/16-bit). |
| Memory (RAM/ROM) | Very small volatile/non-volatile storage (KBytes). |
| Hardware Area | Minimal gate count (GE) for ASIC/FPGA. |
| Cost | Must be extremely low per unit. |
Why Traditional Cryptography (AES, RSA, SHA-2) is Unsuitable
-
High Computational/Energy Cost: AES-128 requires ~1000-2000 GE; RSA operations are prohibitively expensive.
-
Large Memory Footprint: AES-128 code size ~3-10 KB; large lookup tables (S-Boxes) exceed ROM.
-
Unsuitable Hardware Characteristics: Not optimized for bit-level operations or minimal gate count.
Key Evaluation Metrics
-
Gate Equivalents (GE): Hardware area measure.
-
RAM/ROM Usage: Bytes of memory.
-
Energy Consumption: Picojoules per bit (pJ/bit).
-
Throughput: Bits per second (bps) at a given area/power.
-
Latency: Time for one encryption/operation.
-
"Operation": A basic computational step (e.g., one S-Box lookup, one round, one permutation layer).
[!TIP] Exam Focus: Be ready to define "operation" in the context of a specific cipher's round function.
II. Lightweight Block Ciphers: Design & Examples
Core Design Strategies
| Strategy | ARX (Add-Rotate-XOR) | SPN (Substitution-Permutation) | Feistel |
|---|---|---|---|
| Hardware | Moderate GE, no S-Boxes | Can be minimal with small S-Boxes | Often larger due to round function duplication |
| Software | Very efficient on 32/64-bit | Can be slow if small S-Boxes | Good for small block sizes |
| Examples | SPECK, SIMON | PRESENT, GIFT | CLEFIA, DESL |
Component Optimization:
-
S-Box: Small (4-bit or 8-bit), hardware-friendly (bit-sliced), or software-optimized (lookup table). Trade-off: Security vs. Size.
-
Permutation/Layer: Simple linear layer (bit permutation, lightweight MDS matrix) for diffusion at minimal cost.
-
Key Schedule: Lightweight (simple, low memory) vs. Secure (resists related-key attacks). Often a major trade-off point.
-
Round Function: Minimize operations per round (e.g., single S-Box layer, simple linear layer).
-
Parameters: Often smaller block size (64-bit) and key size (80/128-bit).
Analysis of Specific Cipher Families
1. PRESENT
-
Structure: SPN.
-
Parameters: 64-bit block, 80/128-bit key, 31 rounds.
-
Components:
-
4-bit S-Box (optimized for hardware).
-
Bit permutation layer (simple wiring).
-
Key schedule: 31 round keys generated from master key.
-
-
Design Philosophy: Extreme hardware minimalism (target ~1000 GE). Sacrifices some speed/software efficiency.
2. CLEFIA
-
Structure: Feistel-like (type-2 Feistel network).
-
Parameters: 128-bit block, 128/192/256-bit key, 18/22/26 rounds.
-
Components:
-
Two 8-bit S-Boxes (software-friendly for 8-bit CPUs).
-
Flexible key schedule with two F-functions.
-
-
Design Philosophy: Software efficiency on 8-bit microcontrollers while maintaining security.
3. DESL / DESXL
-
Philosophy: Reuse and optimize existing, well-analyzed components (DES S-Boxes).
-
DESL: Uses a single 8-bit S-Box repeatedly in each round to reduce hardware area.
-
DESXL: Uses modified S-Boxes and a more secure key schedule than DESL.
-
Goal: Leverage years of cryptanalysis on DES core while achieving lightweight implementation.
Modes of Operation for Lightweight Block Ciphers
-
Purpose: Extend block cipher to encrypt data > block size.
-
Preferred Mode: CTR (Counter) Mode.
-
Why: Parallelizable (low latency), random access, no propagation delay.
-
Implementation:
Ciphertext = Plaintext ⊕ Encrypt(IV || Counter). -
Example: PRESENT-CTR. Critical: Secure nonce/IV management on constrained devices (no space for large counters).
-
-
Avoid: ECB (insecure), CBC (sequential, higher latency).
Role of Open Design and Public Cryptanalysis
-
Importance: Public scrutiny is essential for discovering flaws and building trust. "Security through obscurity" fails.
-
History: Many lightweight ciphers have been broken (e.g., related-key attacks on SIMON/SPECK, meet-in-the-middle on PRESENT variants).
-
Design Balance: Simplicity aids analysis but may reduce security margin. Need sufficient security margin (extra rounds beyond the minimum required).
-
Case Study: SIMON/SPECK (NSA) faced intense public cryptanalysis leading to adjustments and debate over their design process.
[!TIP] Common Pitfall: Confusing the structure (SPN vs. Feistel) with the mode of operation (CTR, CBC). Structure is internal to the cipher; mode is how it's used.
III. Lightweight Key Management
Fundamental Concepts
Key management lifecycle: Generation → Distribution → Storage → Rotation → Revocation → Destruction.
- Challenge in Constrained Devices: Secure storage (limited EEPROM/Flash), true random number generation (TRNG) quality, scalability for millions of devices.
Centralized vs. Distributed Approaches
| Aspect | Centralized (KDC) | Distributed (Pairwise/Group) |
|---|---|---|
| Mechanism | Trusted third party (KDC) shares a key with each node. Nodes request session keys from KDC. | Nodes establish keys directly (e.g., via pre-distributed key matrix, or lightweight asymmetric). |
| Pros | Simple for devices, single policy point, easy revocation. | No single point of failure, better scalability, lower communication overhead for node-to-node. |
| Cons | Single point of failure/attack, scalability bottleneck (KDC load), all traffic passes through KDC. | Complex key establishment, high initial overhead, difficult revocation, vulnerable to node capture (reveals multiple keys). |
| Security | Trust model hinges on KDC security. | Resilience depends on capture resistance of individual nodes. |
Integration with Standard Protocols (IPSec, TLS)
-
Challenges: Handshake overhead (RSA/ECDH certificates are large), session resumption cost.
-
Lightweight Adaptations:
-
Pre-Shared Key (PSK) Mode: Bypass expensive handshake. Use a pre-shared symmetric key.
-
Session Resumption: Use lightweight session tickets (encrypted with a group key).
-
Cipher Suite Selection: Negotiate lightweight ciphers (e.g., PRESENT, CLEFIA) and hash (e.g., PHOTON) in the record layer.
-
Elliptic Curves: Use efficient curves like Curve25519 for ECDH if asymmetric is needed.
-
Lightweight Group Key Management for IoT Key Evaluation Considerations for a New Protocol:
-
Scalability: How does communication overhead grow with group size N? (e.g., O(N) vs O(log N)).
-
Rekeying Efficiency: Cost to change group key (forward/backward secrecy). Message count and size.
-
Resilience to Node Capture: How many keys are compromised if one node is captured?
-
Communication Overhead: Number of messages and total bytes transmitted per join/leave.
-
Computational Cost: Operations required on the constrained device (e.g., encryptions, MACs).
-
Dynamic Membership: Support for efficient joins and leaves.
Integration of Symmetric Key Management
-
Use a centralized group manager (like a KDC but for groups).
-
Manager encrypts the new group key with each member's individual symmetric key (from a pre-distribution or prior pairwise key).
-
Logical Key Hierarchy (LKH): Adapt LKH tree where each node stores keys for its path. Rekeying only affects nodes on affected path (O(log N) messages). Requires secure key storage per node.
-
Example: A gateway (manager) holds a group key KG. When a node joins, manager sends KG encrypted with that node's unique key Ki.
IV. Other Lightweight Primitives & Considerations
Lightweight Cryptographic Hash Functions
-
Purpose: Integrity, HMAC, digital signatures (with asymmetric), commitment schemes.
-
Design Strategies:
-
Reduced rounds (e.g., PHOTON-256/32).
-
Smaller internal state (e.g., 256-bit vs. 512-bit).
-
Lightweight S-Boxes and permutations.
-
-
Examples & Applications:
-
PHOTON: Sponge-based, used in RFID authentication.
-
SPONGENT: Ultra-lightweight for RFID.
-
QUARK: For embedded systems.
-
Application: Lightweight HMAC for securing IoT MQTT/CoAP messages.
-
Lightweight Stream Ciphers
-
Design: Small internal state (n bits), efficient update function (LFSR, NLFSR, asynchronous).
-
Vulnerability: Birthday Attack & State Collisions
-
Principle: After generating ~$$\displaystyle 2^{n/2} $$ output bits, two different internal states are likely to produce the same output sequence (collision) due to the birthday paradox.
-
Consequence: Attacker can recover the key/state by identifying collisions.
-
Design Optimization: Ensure state size n ≥ 128 bits for long-term security. Or, design the cipher to refresh state from key/IV periodically to limit output per state.
-
-
Examples: Trivium (eSTREAM), Grain (eSTREAM), MICKEY.
Symmetric vs. Asymmetric Cryptography
| Feature | Symmetric | Asymmetric (Lightweight ECC) |
|---|---|---|
| Key | Same secret key for encryption/decryption. | Public key / Private key pair. |
| Speed | Very fast (hardware/software). | 100-1000x slower than symmetric. |
| Use Case | Bulk data encryption, MACs. | Initial key exchange, digital signatures. |
| Lightweight Choice | PRESENT, CLEFIA, LEA, CHAM. | Elliptic Curve Cryptography (ECC) with small curves (e.g., Curve25519, NIST P-256). |
Security Threats Specific to Tiny Devices
-
Physical Attacks:
-
Side-Channel: Power analysis (SPA/DPA), timing attacks, electromagnetic (EM) analysis.
-
Fault Injection: Laser/voltage glitch to induce errors and reveal secrets.
-
Micro-probing: Physical access to chip internals.
-
-
Software Attacks: Memory corruption, code reuse attacks (ROP), buffer overflows in firmware.
-
Network Attacks: Replay, DoS (exhaust battery), but impact is amplified due to limited resources.
-
Supply Chain & Cloning: Devices can be cloned if unique keys are not securely injected.
[!TIP] Exam Winner: Always link a threat to the constraint it exploits (e.g., side-channel → low power makes measurements easier; DoS → limited battery).
BOXED: Critical Formulas & Definitions
-
Birthday Bound for Stream Ciphers: For an n-bit internal state, state collisions become probable after generating approximately $$\displaystyle \boxed{2^{n/2}} $$ output bits.
-
Definition of "Operation": In lightweight cipher evaluation, an "operation" refers to a fundamental computational step of the algorithm, such as a single S-Box substitution, one round of the cipher, or one application of the linear diffusion layer.
-
CTR Mode Encryption:
$$C_i = P_i \oplus E_K(IV \parallel \text{Counter}_i)$$
- Key Management Core Challenge: Securely establishing and maintaining secret keys on devices with limited secure storage and computational capacity.