« 米国 CISA他 OT所有者および運営者向け資産インベントリガイダンス (2025.08.13) | Main | 英国 融合技術のセキュリティ確保:専門家による見解 (2025.08.08) »

2025.08.17

米国 NIST SP 800-232 制約のあるデバイス向けの Ascon ベースの軽量暗号標準:認証付き暗号化、ハッシュ、および拡張可能な出力機能

こんにちは、丸山満彦です。

NISTが、IoTなどでの利用を想定した軽量暗号アルゴリズムの標準として、Asconベースの暗号をNISTは採用していますが、標準としてSP 800-232を今回発表していますね...

 

NIST - ITL

・2025.08.13 NIST SP 800-232 Ascon-Based Lightweight Cryptography Standards for Constrained Devices: Authenticated Encryption, Hash, and Extendable Output Functions

 

NIST SP 800-232 Ascon-Based Lightweight Cryptography Standards for Constrained Devices: Authenticated Encryption, Hash, and Extendable Output Functions NIST SP 800-232 制約のあるデバイス向けの Ascon ベースの軽量暗号標準:認証付き暗号化、ハッシュ、および拡張可能な出力機能
Abstract 要約
In 2023, the National Institute of Standards and Technology (NIST) announced the selection of the Ascon family of algorithms designed by Dobraunig, Eichlseder, Mendel, and Schläffer to provide efficient cryptographic solutions for resource-constrained devices. This decision emerged from a rigorous, multi-round lightweight cryptography standardization process. The Ascon family includes a suite of cryptographic primitives that provide Authenticated Encryption with Associated Data (AEAD), hash function, and eXtendable Output Function (XOF) capabilities. The Ascon family is characterized by lightweight, permutation-based primitives and provides robust security, efficiency, and flexibility, making it ideal for resource-constrained environments, such as Internet of Things (IoT) devices, embedded systems, and low-power sensors. The family is developed to offer a viable alternative when the Advanced Encryption Standard (AES) may not perform optimally. This standard outlines the technical specifications and security properties of Ascon-AEAD128, Ascon-Hash256, Ascon-XOF128, and Ascon-CXOF128. 2023年、米国国立標準技術研究所(NIST)は、リソースに制約のあるデバイス向けに効率的な暗号ソリューションを提供するために、Dobraunig、Eichlseder、Mendel、およびSchläfferによって設計されたAsconファミリーのアルゴリズムの採用を発表した。この決定は、厳格な多段階の軽量暗号標準化プロセスを経て下された。Ascon ファミリーには、関連データ付き認証付き暗号化 (AEAD)、ハッシュ関数、および拡張出力関数 (XOF) 機能を提供する一連の暗号プリミティブが含まれている。Ascon ファミリーは、軽量で順列ベースのプリミティブを特徴とし、堅牢なセキュリティ、効率性、および柔軟性を提供するため、モノのインターネット (IoT) デバイス、組み込みシステム、低電力センサーなどのリソースに制約のある環境に最適である。このファミリーは、Advanced Encryption Standard (AES) が最適に機能しない場合に、実行可能な代替手段を提供するために開発された。この標準は、Ascon-AEAD128、Ascon-Hash256、Ascon-XOF128、および Ascon-CXOF128 の技術仕様とセキュリティ特性を概説している。

 

・[PDF] NIST.SP.800-232

20250815-204027

 

目次...

1. Introduction 1. 序論
2. Preliminaries 2. 予備知識
2.1. Auxiliary Functions 2.1. 補助機能
3. Ascon Permutations 3. Ascon 置換
3.1. Internal State 3.1. 内部状態
3.2. Constant-Addition Layer 𝑝𝐶 3.2. 定数加算層 𝑝𝐶
3.3. Substitution Layer 𝑝𝑆 3.3. 置換層 𝑝𝑆
3.4. Linear Diffusion Layer 𝑝𝐿 3.4. 線形拡散層 𝑝𝐿
4. Authenticated Encryption Scheme: Ascon-AEAD128 4. 認証付き暗号方式:Ascon-AEAD128
4.1. Specification of Ascon-AEAD128 4.1. Ascon-AEAD128 の仕様
4.1.1. Encryption 4.1.1. 暗号化
4.1.2. Decryption 4.1.2. 復号
4.2. Implementation Options 4.2. 実装オプション
4.2.1. Truncation 4.2.1. 切り捨て
4.2.2. Nonce Masking 4.2.2. ノンスのマスキング
4.3. AEAD Requirements 4.3. AEAD の要件
4.4. Security Properties 4.4. セキュリティ特性
4.4.1. Single-Key Setting 4.4.1. 単一鍵設定
4.4.2. Multi-Key Setting 4.4.2. 複数鍵設定
4.4.3. Nonce-Misuse Setting 4.4.3. ノンスの悪用設定
5. Hash and eXtendable-Output Functions (XOFs) 5. ハッシュおよび拡張出力関数 (XOF)
5.1. Specification of Ascon-Hash256 5.1. Ascon-Hash256 の仕様
5.2. Specification of Ascon-XOF128 5.2. Ascon-XOF128 の仕様
5.3. Specification of Ascon-CXOF128 5.3. Ascon-CXOF128 の仕様
5.4. Streaming API for XOF 5.4. XOF のストリーミング API
5.5. Security Strengths 5.5. セキュリティ強度
6. Conformance 6. 適合性
Appendix A. Implementation Notes 附属書 A. 実装に関する注記
A.1. Conversion Functions A.1. 変換関数
A.2. Implementing with Integers A.2. 整数による実装
A.3. Precomputation A.3. 事前計算
Appendix B. Determination of the Initial Values 附属書 B. 初期値の決定

 

 

序論...

1. Introduction 1. 序論
This standard specifies the Ascon family of algorithms to provide Authenticated Encryption with Associated Data (AEAD), a hash function, and two eXtendable Output Functions (XOFs). The Ascon family is designed to be efficient in constrained environments. The algorithms included in this standard are as follows: この標準は、関連データ付き認証付き暗号化(AEAD)、ハッシュ関数、および 2 つの拡張出力関数(XOF)を提供する Ascon ファミリのアルゴリズムを規定する。Ascon ファミリは、制約のある環境でも効率的に動作するように設計されている。この標準に含まれるアルゴリズムは、次のとおりである。
1. Ascon-AEAD128 is a nonce-based AEAD scheme, offering 128-bit security strength in the single-key setting. 1. Ascon-AEAD128 は、ノンスベースの AEAD スキームであり、単一鍵設定で 128 ビットのセキュリティ強度を提供する。
2. Ascon-Hash256 is a cryptographic hash function that produces a 256-bit hash of the input messages, offering a security strength of 128 bits. 2. Ascon-Hash256 は、入力メッセージの 256 ビットのハッシュを生成する暗号ハッシュ関数であり、128 ビットのセキュリティ強度を提供する。
3. Ascon-XOF128 is a XOF, where the output size of the hash of the message can be selected by the user, and the supported security strength is up to 128 bits. 3. Ascon-XOF128 は、メッセージのハッシュの出力サイズをユーザーが選択できる XOF です。サポートされるセキュリティ強度は最大 128 ビットである。
4. Ascon-CXOF128 is a customized XOF that allows users to specify a customization string and choose the output size of the message hash. It supports a security strength of up to 128 bits. 4. Ascon-CXOF128 は、ユーザーがカスタマイズ文字列を指定し、メッセージハッシュの出力サイズを選択できるカスタマイズ可能な XOF である。最大 128 ビットのセキュリティ強度をサポートする。
Development of the Ascon family. Ascon (version v1) [1] was first submitted to CAESAR (Competition for Authenticated Encryption: Security, Applicability, and Robustness)   in 2014. The submission included two AEAD algorithms: a primary recommendation, Ascon-128, with a 128-bit key and the secondary recommendation, Ascon-96, with a 96-bit key. Updated versions v1.1 [2] for Round 2 and v1.2 [3] for Round 3 included minor tweaks, such as reordering the round constants, and the secondary recommendation was updated to Ascon-128a. In 2019, Ascon-128 and Ascon-128a were selected as the first choice for the lightweight authenticated encryption use case in the final portfolio of the CAESAR competition. Ascon ファミリーの開発。Ascon (バージョン v1) [1] は、2014 年に CAESAR (認証付き暗号化コンペティション:セキュリティ、適用性、および堅牢性) に初めて提出された。提出には2つのAEADアルゴリズムが含まれていた:主要な推奨アルゴリズムであるAscon-128(128ビット鍵)と、二次推奨アルゴリズムであるAscon-96(96ビット鍵)である。第2ラウンド向けのバージョンv1.1 [2]と第3ラウンド向けのバージョンv1.2 [3]では、ラウンド定数の再配置など minor な変更が加えられ、二次推奨アルゴリズムはAscon-128aに更新された。2019 年、Ascon-128 および Ascon-128a は、CAESAR コンテストの最終ポートフォリオにおいて、軽量認証付き暗号化のユースケースの第一候補として選定された。
NIST Lightweight Cryptography Standardization Process. In 2015, the National Institute of Standards and Technology (NIST) initiated the Lightweight Cryptography Standardization Process to develop cryptographic standards that are suitable for constrained environments in which conventional cryptographic standards (e.g., AES-GCM [4, 5], SHA-2 [6] and SHA-3 [7] hash function families) may be resource-intensive. In February 2023, NIST announced the decision to standardize the Ascon family [8] for lightweight cryptography applications. For more information, refer to NIST Internal Report (IR) 8268 [9], IR 8369 [10], and IR 8454 [11]. NIST 軽量暗号標準化プロセス。2015 年、米国国立標準技術研究所(NIST)は、従来の暗号標準(AES-GCM [4、5]、SHA-2 [6]、SHA-3 [7] ハッシュ関数ファミリーなど)がリソースを大量に消費する制約のある環境に適した暗号標準を開発するため、軽量暗号標準の標準化プロセスを開始した。2023年2月、NIST は、軽量暗号アプリケーション用の Ascon ファミリ [8] を標準化することを決定した。詳細については、NIST 内部報告書 (IR) 8268 [9]、IR 8369 [10]、および IR 8454 [11] を参照のこと。
Differences from the Ascon submission v1.2. The technical differences between this standard and the Ascon submission [8] are provided below: Ascon 提出版 v1.2 との相違点。この標準と Ascon 提出版 [8] との技術的な相違点は、以下の通りである。
1. Permutations. The Ascon submission defined three Ascon permutations with 6, 8, and 12 rounds. This standard specifies additional Ascon permutations by providing round constants for up to 16 rounds to accommodate potential functionality extensions in the future. 1. 順列。Ascon 提出版では、6、8、12 ラウンドの 3 つの Ascon 順列が定義されていた。この標準では、将来の機能拡張に対応するため、最大 16 ラウンドまでのラウンド定数を規定し、追加の Ascon 順列を規定している。
2. AEAD variants. The Ascon submission package defined AEAD variants ASCON-128, ASCON-128a, and ASCON-80pq. This standard specifies the Ascon-AEAD128 algorithm, which is based on ASCON-128a.  2. AEAD の変種。Ascon 提出パッケージでは、AEAD 変種 ASCON-128、ASCON-128a、および ASCON-80pq を定義してした。この標準では、ASCON-128a に基づく Ascon-AEAD128 アルゴリズムを規定している。
3. Hash function variants. The Ascon submission defined ASCON-HASH and ASCON-HASHA. This standard specifies Ascon-Hash256, which is based on ASCON-HASH.  3. ハッシュ関数の変種。Ascon 提出では、ASCON-HASH および ASCON-HASHA を定義してした。この標準は、ASCON-HASH に基づく Ascon-Hash256 を規定している。
4. XOF variants. The Ascon submission defined two XOFs, ASCON-XOF and ASCON-XOFA. This standard specifies Ascon-XOF128, which is based on ASCON-XOF, and a new customized XOF, Ascon-CXOF128. 4. XOF の変種。Ascon 提出文書では、ASCON-XOF および ASCON-XOFA の 2 つの XOF を定義していた。この標準は、ASCON-XOF に基づく Ascon-XOF128 および新しいカスタマイズされた XOF、Ascon-CXOF128 を規定している。
5. Initial values. The initial values of the algorithms have been updated to support a new format that accommodates potential functionality extensions. 5. 初期値。アルゴリズムの初期値が、機能拡張に対応するための新しい形式に対応するように更新された。
6. Endianness. The endianness has been switched from big endian to little endian to improve performance on little-endian microcontrollers. 6. エンディアン。リトルエンディアンマイクロコントローラのパフォーマンスを向上させるため、エンディアンがビッグエンディアンからリトルエンディアンに変更された。
7. Truncation and nonce masking. The implementation options of Ascon-AEAD128 with truncation and nonce masking have been added. 7. 切り捨ておよびノンスのマスキング。切り捨ておよびノンスのマスキング機能を備えた Ascon-AEAD128 の実装オプションが追加された。
Main features of Ascon. The main features of the Ascon family are: Ascon の主な機能。Ascon ファミリの主な機能は次のとおりである。
• Multiple functionalities. The same permutations are used to construct multiple functionalities, which allows an implementation of AEAD, hash, and XOF functionalities to share logic and, therefore, have a more compact implementation than functions that were developed independently. • 複数の機能。同じ順列を使用して複数の機能を構築できるため、AEAD、ハッシュ、および XOF 機能を実装する際にロジックを共有でき、個別に開発された機能よりも実装をコンパクトにすることができる。
• Online and single pass. Ascon-AEAD128 is online, meaning that the 𝑖-th ciphertext block is determined by the key, nonce, associated data, and first 𝑖 plaintext blocks. Ascon family members require only a single pass over the data. • オンラインおよびシングルパス。Ascon-AEAD128 はオンラインであり、𝑖 番目の暗号文ブロックは、鍵、ノンス、関連データ、および最初の 𝑖 個の平文ブロックによって決定される。Ascon ファミリーのメンバーは、データを 1 回だけ通過するだけで済む。
• Inverse-free. Since all of the Ascon family members only use the underlying permutations in the forward direction, implementing the inverse permutations is not needed. 逆変換不要。Ascon ファミリーのメンバーはすべて、基礎となる順方向の順列のみを使用するため、逆順列を実装する必要はない。
Organization. Section 2 provides preliminaries, including the acronyms, terms, definitions, notation, basic operations, and auxiliary functions. Section 3 specifies the Ascon permutations for up to 16 rounds. Section 4 specifies the Ascon-AEAD128AEAD scheme, provides some implementation options for truncation and nonce masking, lists the requirements for validation, and provides security properties. Section 5 specifies the Ascon-Hash256 hash function, the Ascon-XOF128 XOF, and the Ascon-CXOF128 customized XOF and describes their security properties. Section 6 provides information about conformance. Appendix A provides additional notes and conversion functions for implementations. Appendix B provides additional information regarding the construction of initial values. 構成。セクション2では、頭字語、用語、定義、表記法、基本操作、および補助関数などの予備知識について説明する。セクション3では、最大 16 ラウンドの Ascon 置換を規定する。セクション4では、Ascon-AEAD128AEAD スキームを規定し、切り捨ておよびノンスのマスキングに関するいくつかの実装オプションを示し、妥当性確認の要件を列挙し、セキュリティ特性を示す。セクション5では、Ascon-Hash256 ハッシュ関数、Ascon-XOF128 XOF、および Ascon-CXOF128 カスタマイズ XOF を規定し、それらのセキュリティ特性を説明する。セクション6では、適合性に関する情報を提供する。附属書 Aでは、実装に関する追加情報および変換関数を規定する。附属書 Bでは、初期値の構築に関する追加情報を提供する。

 

 

 


 

まるちゃんの情報セキュリティ気まぐれ日記

Asconファミリー...

・2024.11.14 米国 NIST NIST SP 800-232(初期公開ドラフト) 制約されたデバイスのためのAsconベースの軽量暗号標準: 認証された暗号化、ハッシュ、拡張可能な出力機能

・2024.05.24 米国 NIST SP 800-229 2023会計年度サイバーセキュリティとプライバシー年次報告書

・2023.06.24 NIST NISTIR 8454 NIST 軽量暗号標準化プロセスの最終ラウンドに関する状況報告書

・2023.02.12 NIST 標準軽量暗号はAsconファミリーから... (2023.02.07)

 

|

« 米国 CISA他 OT所有者および運営者向け資産インベントリガイダンス (2025.08.13) | Main | 英国 融合技術のセキュリティ確保:専門家による見解 (2025.08.08) »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 米国 CISA他 OT所有者および運営者向け資産インベントリガイダンス (2025.08.13) | Main | 英国 融合技術のセキュリティ確保:専門家による見解 (2025.08.08) »