<p><InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_372_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="67" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GIFT\text {-}128}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GIFT</mi> <mtext mathvariant="sans-serif">-</mtext> <mn mathvariant="sans-serif">128</mn> </mrow> </math></EquationSource> </InlineEquation> is a lightweight block cipher published in CHES 2017 and is known to have optimal structure for efficient hardware implementations. On the other hand, the software implementation of <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_372_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="67" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GIFT\text {-}128}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GIFT</mi> <mtext mathvariant="sans-serif">-</mtext> <mn mathvariant="sans-serif">128</mn> </mrow> </math></EquationSource> </InlineEquation> is known to be complex due to the bit permutation of the permutation layer. In software implementation, an efficient bitslice implementation on 32-bit ARM processor can be achieved by using the Fixslicing representation published in CHES 2020, but it is difficult to achieve similar efficiency on a 64-bit ARM processor. For an efficient <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_372_Article_IEq3.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="67" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GIFT\text {-}128}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GIFT</mi> <mtext mathvariant="sans-serif">-</mtext> <mn mathvariant="sans-serif">128</mn> </mrow> </math></EquationSource> </InlineEquation> implementation on 64-bit processors, we encrypt two blocks in parallel, called double-block encryption, but the efficiency depends on the interleave size because of the permutation layer. In this paper, we theoretically analyze how the interleave size of two blocks affects operations of permutation layer in <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_372_Article_IEq4.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="67" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GIFT\text {-}128}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GIFT</mi> <mtext mathvariant="sans-serif">-</mtext> <mn mathvariant="sans-serif">128</mn> </mrow> </math></EquationSource> </InlineEquation> on 64-bit ARM processor. Considering the characteristics of the permutation layer, we identify six possible interleave sizes that can be efficient. We then implement all the cases and compare their performance. The best case provides 12% of improvement compared to the worst case. Noticeably, the implementation also shows that the speed of the proposed best case is twice as fast as single-block encryption on 64-bit ARM processor. As far as we know, this is the first implementation of <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="13389_2025_372_Article_IEq5.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="67" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GIFT\text {-}128}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GIFT</mi> <mtext mathvariant="sans-serif">-</mtext> <mn mathvariant="sans-serif">128</mn> </mrow> </math></EquationSource> </InlineEquation> on 64-bit ARM processor and the proposed idea can be easily extended to typical 64-bit CPUs.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Best interleave size of GIFT-128 on 64-bit ARM processor

  • Myeonghoon Lee,
  • Hanbeom Shin,
  • Myoungsu Shin,
  • Dongjae Lee,
  • Seog Chung Seo,
  • Seokhie Hong

摘要

\(\mathsf {GIFT\text {-}128}\) GIFT - 128 is a lightweight block cipher published in CHES 2017 and is known to have optimal structure for efficient hardware implementations. On the other hand, the software implementation of \(\mathsf {GIFT\text {-}128}\) GIFT - 128 is known to be complex due to the bit permutation of the permutation layer. In software implementation, an efficient bitslice implementation on 32-bit ARM processor can be achieved by using the Fixslicing representation published in CHES 2020, but it is difficult to achieve similar efficiency on a 64-bit ARM processor. For an efficient \(\mathsf {GIFT\text {-}128}\) GIFT - 128 implementation on 64-bit processors, we encrypt two blocks in parallel, called double-block encryption, but the efficiency depends on the interleave size because of the permutation layer. In this paper, we theoretically analyze how the interleave size of two blocks affects operations of permutation layer in \(\mathsf {GIFT\text {-}128}\) GIFT - 128 on 64-bit ARM processor. Considering the characteristics of the permutation layer, we identify six possible interleave sizes that can be efficient. We then implement all the cases and compare their performance. The best case provides 12% of improvement compared to the worst case. Noticeably, the implementation also shows that the speed of the proposed best case is twice as fast as single-block encryption on 64-bit ARM processor. As far as we know, this is the first implementation of \(\mathsf {GIFT\text {-}128}\) GIFT - 128 on 64-bit ARM processor and the proposed idea can be easily extended to typical 64-bit CPUs.