Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang
Abstract
S-boxes are the only source of non-linearity in many symmetric primitives. While they are often defined as being functions operating on a small space, some recent designs propose the use of much larger ones (e.g., 32 bits). In this context, an S-box is then defined as a subfunction whose cryptographic properties can be estimated precisely.
We present a 64-bit ARX-based S-box called Alzette, which can be evaluated in constant time using only 12 instructions on modern CPUs. Its parallel application can also leverage vector (SIMD) instructions. One iteration of Alzette has differential and linear properties comparable to those of the AES S-box, and two are at least as secure as the AES super S-box. As the state size is much larger than the typical 4 or 8 bits, the study of the relevant cryptographic properties of Alzette is not trivial.
We further discuss how such wide S-boxes could be used to construct round functions of 64-, 128- and 256-bit (tweakable) block ciphers with good cryptographic properties that are guaranteed even in the related-tweak setting. We use these structures to design a very lightweight 64-bit block cipher (CRAX) which outperforms SPECK-64/128 for short messages on micro-controllers, and a 256-bit tweakable block cipher (TRAX) which can be used to obtain strong security guarantees against powerful adversaries (nonce misuse, quantum attacks).
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6db3a1b3-fd36-4912-8de9-4b49c63fe620Cited by top-tier papers3
- Shorter Signatures Based on Tailor-Made Minimalist Symmetric-Key CryptoChristoph Dobraunig, Daniel Kales, Christian Rechberger, Markus Schofnegger et al.CCS 2022 · 36 citations
- Rotational Differential-Linear Distinguishers of ARX Ciphers with Arbitrary Output Linear MasksZhongfeng Niu, Siwei Sun, Yunwen Liu, Chao LiCRYPTO 2022 · 29 citations
- EasyBC: A Cryptography-Specific Language for Security Analysis of Block Ciphers against Differential CryptanalysisPu Sun, Fu Song, Yuqi Chen, Taolue ChenPOPL 2024 · 4 citations
Related papers
- Algorithmic Toolkit for Linearization of S-BoxesAlex Biryukov, Philip Turecek, Aleksei UdovenkoEUROCRYPT 2026
- Implicit White-Box Implementations: White-Boxing ARX CiphersAdrián Ranea, Joachim Vandersmissen, Bart PreneelCRYPTO 2022 · 15 citations
- Thinking Outside the SuperboxNicolas Bordes, Joan Daemen, Daniël Kuijsters, Gilles Van AsscheCRYPTO 2021 · 15 citations
- Efficient Detection of High Probability Statistical Properties of Cryptosystems via Surrogate DifferentiationItai Dinur, Orr Dunkelman, Nathan Keller, Eyal Ronen et al.EUROCRYPT 2023 · 5 citations
- On a Generalization of Substitution-Permutation Networks: The HADES Design StrategyLorenzo Grassi, Reinhard Lüftenegger, Christian Rechberger, Dragos Rotaru et al.EUROCRYPT 2020 · 77 citations
