1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
|
v1.1
====
ref
---
### Fixes
These modifications change the algorithm's output.
- Change alpha coefficients in tweakey schedule to ensure lane 0 is updated between each round:
- lane 0: Id => M
- lane 1: M => M^2
- lane 2: M^2 => M^3
- lane 3: M^3 => M^4
- lane 4: M_R (unchanged)
- lane 5: M_R^2 (unchanged)
- lane 6: M_R^3 (unchanged)
(multiplications.h, tweakey.c)
### Cleanups
These modifications are structural and/or stylistic and do not change the algorithm's ouptut.
- Introduce helper function copy_block_index() to make tweak-building functions more legible.
(lilliput-ae-utils.h, lilliput-i.c, lilliput-ii.c)
- Initialize ΘCB3 tweak with nonce instead of copying the latter into the latter repeatedly.
(lilliput-i.c)
- Re-write _nonlinear_layer() and _linear_layer() functions to better resemble the specification.
(cipher.c)
- Extract tweakey multiplications into their own header file, so that other implementations can make more targeted changes.
(constants.h, multiplications.h, tweakey.c)
add_threshold
-------------
### Fixes
See reference implementation.
### Cleanups
See reference implementation. Further cleanups:
- Use size_t to iterate on arrays in lilliput_tbc_encrypt() and lilliput_tbc_decrypt().
(cipher.c)
- Add constant macros KEY_LANES_NB and TWEAK_LANES_NB to make tweakey schedule code more legible.
(tweakey.c)
add_tweakeyloop
---------------
See reference implementation.
add_python
----------
### Fixes
See reference implementation.
### Cleanups
- Re-write tweakey multiplications to better resemble the specification.
(multiplications.py)
add_vhdl
--------
### Reorganization
- A more synthetical organisation was chosen. Indeed, Lilliput-II only need encryption and Lilliput-I need encryption and decryption, so LilliputTBCencrypt is always used for lilliput-I and LilliputTBCencryptdecrypt for Lilliput-II. And LilliputTBCdecrypt is no longer described because no version uses it.
### Fixes
- For all vhdl versions we change coefficients in tweakey schedule to ensure lane 0 is updated between each encryption round:
- lane 0: Id => M
- lane 1: M => M^2
- lane 2: M^2 => M^3
- lane 3: M^3 => M^4
- lane 4: M_R (unchanged)
- lane 5: M_R^2 (unchanged)
- lane 6: M_R^3 (unchanged)
(multiplication.vhd)
- For Lilliput-I we change coefficients in tweakey schedule to ensure lane 0 is updated between each decryption round:
- lane 0: Id => inv(M)
- lane 1: inv(M) => inv(M)^2
- lane 2: inv(M)^2 => inv(M)^3
- lane 3: inv(M)^3 => inv(M)^4
- lane 4: M_R (unchanged)
- lane 5: M_R^2 (unchanged)
- lane 6: M_R^3 (unchanged)
(inv_multiplication.vhd)
### Cleanups
- Merge Sbox in one file.
(sbox.vhd, inner_sbox_a.vhd, inner_sbox_b, vhd,inner_sbox_c.vhd)
- Create registers in file roundexe_lilliput.vhd.
(state_key_register.vhd, state_register.vhd, roundexe_lilliput)
- Reduction of the number of signals.
(chiffrement.vhd)
### Optimizations
- Pipeline RoundTweakey extraction and round function.
(roundexe_lilliput.vhd, machine_etat_chiffrement.vhd)
- Isolate input and output from critical path.
(roundexe_lilliput.vhd, machine_etat_chiffrement.vhd)
v1.0
====
Initial release to round 1 of the LWC standardization process.
|