Designs › Digital
Ascon · SP 800-232
The standardized Ascon family: authenticated encryption, hashing and extendable output, using the reference author's SystemVerilog implementation.
How it works
Ascon combines a small state with repeated nonlinear permutation rounds. AEAD protects confidentiality and checks authenticity; hashing and extendable-output modes use the same permutation family with different initialization and data handling.
- The controller accepts key and typed input blocks through ready/valid handshakes. Byte-valid masks and end markers handle partial blocks.
- Data is absorbed into the 320-bit state. A round adds a constant, applies a nonlinear substitution layer and mixes bits by rotations and XORs.
- The state feeds the permutation and receives the updated state on each round. V1 performs one round per cycle; larger unrolling performs more rounds per cycle at a hardware cost.
- Finalization produces output and an authentication result for AEAD decryption. The application must wait for a valid successful authentication result before releasing decrypted plaintext.
Design decisions and limits
- Use SP 800-232 test vectors and byte ordering. Older Ascon v1.2 vectors and names are not interchangeable with the standardized algorithms.
- Important security boundary: this upstream core emits decrypted plaintext before the tag has been verified. A real application needs a separate buffer that releases data only after authentication succeeds and discards it on failure.
- A correct known-answer test is not evidence of side-channel resistance, fault resistance, nonce management or security certification.
- Bus width and round unrolling trade interface bandwidth, latency, area and timing. No IHP area or frequency is claimed here.
Try it
Flip one ciphertext bit and one tag bit in separate tests. Both must fail authentication, and neither may release plaintext to the application. Then add input and output stalls without changing the result.
What runs in the browser
Pinned upstream source links and an AiSIC teaching explanation only. No RTL bundle, cryptographic validation, simulation result, synthesized netlist or IHP area/delay is provided.
Upstream sources
SP 800-232 · main snapshot e1069549a189 · CC0-1.0 for this implementation. Preserve the author, LICENSE and CITATION.cff; review any additional dependencies separately.
Technology-independent RTL. Open the workspace to run its checks, synthesize it and simulate its delays in your browser.