A Quantitative Security Analysis of S-boxes in the NIST Lightweight Cryptography Finalists

Naseer, Mahnoor;Sundas Tariq;Naveed Riaz;et.al.
(2025) Discover Computing — (2025)

Files

upload.pdf
  • Open Access
  • Adobe PDF
  • 486.94 KB
  • https://creativecommons.org/licenses/by/4.0/

Details

Authors
  • Naseer, Mahnoororcid-logoCrypto Group, ICTEAM Institute, UCLouvain, Louvain-la-Neuve, Belgium
    Author
  • Sundas Tariq3MI Labs and COSIC, KU Leuven, Leuven, Belgium
    Author
  • Naveed RiazSEECS, National University of Sciences and Technology, Islamabad, Pakistan
    Author
  • et. al.
Abstract
Lightweight cryptography was primarily inspired by the design criteria of symmetric cryptography. It plays a vital role in ensuring the security, privacy, and reliability of microelectronic devices without compromising the overall functionality and efficiency. However, the increasingly platform specific design requirements prompted the development of a standard lightweight algorithm. In 2017, NIST put forward security requirements for a standard lightweight scheme — security strength of at least 112 bits against known cryptanalysis attacks; mitigation against side channel and fault injection attacks; implementation efficiency. After three rounds of review, ASCON was crowned as the winner of the competition. Evaluating the individual components used in any cryptographic algorithm is an important step in the verification of security claims. A fundamental component used to ensure Shannon’s property of confusion in cryptographic primitives is an s-box. Hence, the quality of an s-box is a significant contributing factor in the security strength of a cipher. In this paper, we evaluate the s-boxes of 6 NIST LWC competition finalists based on well-known cryptographic properties, and comment on how the results reflect upon NIST security requirements. Our findings have revealed that these s-boxes do not comply with the basic notions of avalanche, making it vulnerable to high-order sophisticated cryptanalysis.
Affiliations

Citations

Naseer, M., Sundas Tariq, Naveed Riaz, & et al. (2025). A Quantitative Security Analysis of S-boxes in the NIST Lightweight Cryptography Finalists. Discover Computing. Accepted/in-press. https://doi.org/10.1007/s10791-025-09721-z (Original work published 2025)