An Automatic Search Method for 4-Bit Optimal S-Boxes Towards Considering Cryptographic Properties and Hardware Area Simultaneously
摘要
For lightweight cryptographic primitives, both cryptographic properties and hardware implementation are objectives to be considered. 4-bit optimal S-box, because of good cryptographic properties and compactness in hardware, becomes the main nonlinear block in lightweight primitives. Up to now, there are lots of methods to design 4-bit optimal S-box. However, most of them only consider cryptographic properties, but less hardware implementation performance. In this paper, we propose a general automatic search method for 4-bit optimal S-box based on STP, which can simultaneously consider cryptographic properties and hardware area for the first time. With this method, we can further seek lower bound of hardware implementation area. As a result, we find out several more lightweight 4-bit optimal S-boxes without fixed point, which only need 12.33GE under the UMC 180 nm standard library. As far as we know, they are smaller than all existed same kind of S-boxes such as the ones used in SKINNY and PICCOLO ciphers.