summaryrefslogtreecommitdiff
path: root/CHANGELOG.txt
blob: 7d7413f9b00070d82cd29e232f97c7f87ef9786c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
v1.1
====

ref
---

### Fixes

These modifications change the algorithm's output.

- Change alpha coefficients in tweakey schedule to ensure lane 0 is updated between each round:
    - lane 0: Id  => M
    - lane 1: M   => M^2
    - lane 2: M^2 => M^3
    - lane 3: M^3 => M^4
    - lane 4: M_R   (unchanged)
    - lane 5: M_R^2 (unchanged)
    - lane 6: M_R^3 (unchanged)
  (multiplications.h, tweakey.c)

### Cleanups

These modifications are structural and/or stylistic and do not change the algorithm's ouptut.

- Introduce helper function copy_block_index() to make tweak-building functions more legible.
  (lilliput-ae-utils.h, lilliput-i.c, lilliput-ii.c)

- Initialize ΘCB3 tweak with nonce instead of copying the latter into the latter repeatedly.
  (lilliput-i.c)

- Re-write _nonlinear_layer() and _linear_layer() functions to better resemble the specification.
  (cipher.c)

- Extract tweakey multiplications into their own header file, so that other implementations can make more targeted changes.
  (constants.h, multiplications.h, tweakey.c)

add_threshold
-------------

### Fixes

See reference implementation.

### Cleanups

See reference implementation. Further cleanups:

- Use size_t to iterate on arrays in lilliput_tbc_encrypt() and lilliput_tbc_decrypt().
  (cipher.c)

- Add constant macros KEY_LANES_NB and TWEAK_LANES_NB to make tweakey schedule code more legible.
  (tweakey.c)

add_tweakeyloop
---------------

See reference implementation.

add_python
----------

### Fixes

See reference implementation.

### Cleanups

- Re-write tweakey multiplications to better resemble the specification.
  (multiplications.py)

add_vhdl
--------

### Reorganization

- A more synthetical organisation was chosen. Indeed, Lilliput-II only need encryption and Lilliput-I need encryption and decryption, so LilliputTBCencrypt is always used for lilliput-I and LilliputTBCencryptdecrypt for Lilliput-II. And LilliputTBCdecrypt is no longer described because no version uses it.

### Fixes

- For all vhdl versions we change coefficients in tweakey schedule to ensure lane 0 is updated between each encryption round:
    - lane 0: Id  => M
    - lane 1: M   => M^2
    - lane 2: M^2 => M^3
    - lane 3: M^3 => M^4
    - lane 4: M_R   (unchanged)
    - lane 5: M_R^2 (unchanged)
    - lane 6: M_R^3 (unchanged)
  (multiplication.vhd)

- For Lilliput-I we change coefficients in tweakey schedule to ensure lane 0 is updated between each decryption round:
    - lane 0: Id       => inv(M)
    - lane 1: inv(M)   => inv(M)^2
    - lane 2: inv(M)^2 => inv(M)^3
    - lane 3: inv(M)^3 => inv(M)^4
    - lane 4: M_R      (unchanged)
    - lane 5: M_R^2    (unchanged)
    - lane 6: M_R^3    (unchanged)
  (inv_multiplication.vhd)


  ### Cleanups

  - Merge Sbox in one file.
  (sbox.vhd, inner_sbox_a.vhd, inner_sbox_b, vhd,inner_sbox_c.vhd)

  - Create registers in file roundexe_lilliput.vhd.
  (state_key_register.vhd, state_register.vhd, roundexe_lilliput)

  - Reduction of the number of signals.
  (chiffrement.vhd)

  ### Optimizations

  - Pipeline RoundTweakey extraction and round function.
  (roundexe_lilliput.vhd, machine_etat_chiffrement.vhd)

  - Isolate input and output from critical path.
  (roundexe_lilliput.vhd, machine_etat_chiffrement.vhd)

v1.0
====

Initial release to round 1 of the LWC standardization process.