{
  "$schema": "https://aisic.dev/schemas/digital-ip.schema.json",
  "schema": "aisic.digital-ip/1",
  "recordVersion": 1,
  "entryType": "upstream-ip",
  "id": "ip-ascon",
  "name": "Ascon · SP 800-232",
  "summary": "The standardized Ascon family: authenticated encryption, hashing and extendable output, using the reference author's SystemVerilog implementation.",
  "technology": "Technology-independent RTL",
  "resources": { "record": "/digital/ip-ascon/design.json", "schema": "/schemas/digital-ip.schema.json", "page": "/digital.html#ip-ascon/learn" },
  "upstream": {
    "repository": "https://github.com/rprimas/ascon-verilog",
    "maintainer": "Robert Primas",
    "version": "SP 800-232 · main snapshot e1069549a189",
    "commit": "e1069549a1895f376391530a1842694ea8bb044b",
    "checkedOn": "2026-09-29",
    "selection": "Reference-author repository linked by the official Ascon implementations page and ascon/ascon-hardware. No version tags were advertised when checked. This is not a NIST-maintained repository. The older ascon/ascon-hardware VHDL reference targets Ascon v1.2, not SP 800-232.",
    "license": "CC0-1.0 for this implementation. Preserve the author, LICENSE and CITATION.cff; review any additional dependencies separately.",
    "files": [
      { "path": "README.md", "label": "Modes, interface and integration warnings" },
      { "path": "rtl/ascon_core.sv", "label": "Ascon core RTL" },
      { "path": "rtl/asconp.sv", "label": "Permutation RTL" },
      { "path": "rtl/config.sv", "label": "Bus width, unrolling and constants" },
      { "path": "rtl/functions.sv", "label": "Datapath helper functions" },
      { "path": "rtl/register.sv", "label": "State register RTL" },
      { "path": "test.py", "label": "Upstream cocotb testbench" },
      { "path": "LICENSE", "label": "License" },
      { "path": "CITATION.cff", "label": "Author citation" }
    ]
  },
  "configuration": {
    "name": "V1 · 32-bit bus, one round per cycle (proposed first browser target)",
    "top": "ascon_core",
    "scope": "Begin with V1 and Ascon-AEAD128 known-answer tests; add Hash256, XOF128 and CXOF128 checks separately. This configuration has not been built or simulated by AiSIC.",
    "parameters": { "define": "V1", "CCW": 32, "UROL": 1 }
  },
  "lesson": {
    "idea": "Ascon combines a small state with repeated nonlinear permutation rounds. AEAD protects confidentiality and checks authenticity; hashing and extendable-output modes use the same permutation family with different initialization and data handling.",
    "steps": [
      "The controller accepts key and typed input blocks through ready/valid handshakes. Byte-valid masks and end markers handle partial blocks.",
      "Data is absorbed into the 320-bit state. A round adds a constant, applies a nonlinear substitution layer and mixes bits by rotations and XORs.",
      "The state feeds the permutation and receives the updated state on each round. V1 performs one round per cycle; larger unrolling performs more rounds per cycle at a hardware cost.",
      "Finalization produces output and an authentication result for AEAD decryption. The application must wait for a valid successful authentication result before releasing decrypted plaintext."
    ],
    "tradeoffs": [
      "Use SP 800-232 test vectors and byte ordering. Older Ascon v1.2 vectors and names are not interchangeable with the standardized algorithms.",
      "Important security boundary: this upstream core emits decrypted plaintext before the tag has been verified. A real application needs a separate buffer that releases data only after authentication succeeds and discards it on failure.",
      "A correct known-answer test is not evidence of side-channel resistance, fault resistance, nonce management or security certification.",
      "Bus width and round unrolling trade interface bandwidth, latency, area and timing. No IHP area or frequency is claimed here."
    ],
    "exercise": "Flip one ciphertext bit and one tag bit in separate tests. Both must fail authentication, and neither may release plaintext to the application. Then add input and output stalls without changing the result."
  },
  "diagram": {
    "kind": "conceptual-architecture",
    "scope": "Conceptual AEAD dataflow, not a complete RTL netlist. The state/permutation feedback is essential. The application buffer is a required integration addition, not part of the referenced core; it releases decrypted output only after a valid authentication pass.",
    "nodes": [
      { "id": "input", "label": "Key / typed input", "detail": "Ready / valid", "column": 0, "row": 0 },
      { "id": "state", "label": "320-bit state", "detail": "Absorb / update", "column": 1, "row": 0 },
      { "id": "output", "label": "Output / tag check", "detail": "Data + auth status", "column": 2, "row": 0 },
      { "id": "buffer", "label": "Application buffer", "detail": "Release on auth pass", "column": 3, "row": 0 },
      { "id": "control", "label": "Controller", "detail": "Mode / phase / rounds", "column": 0, "row": 1 },
      { "id": "permutation", "label": "Ascon permutation", "detail": "One round / cycle (V1)", "column": 1, "row": 1 }
    ],
    "edges": [
      { "from": "input", "to": "state", "label": "Key and data absorption" },
      { "from": "state", "to": "output", "label": "Squeeze, encryption/decryption and tag processing" },
      { "from": "output", "to": "buffer", "label": "Decrypted data plus valid authentication status" },
      { "from": "input", "to": "control", "label": "Type, valid-byte and end markers" },
      { "from": "control", "to": "permutation", "label": "Round control" },
      { "from": "state", "to": "permutation", "label": "Permutation input and updated state feedback", "bidirectional": true }
    ]
  },
  "verificationPlan": [
    "Resolve and qualify the exact V1 source list in the browser SystemVerilog toolchain. Keep the source revision and test-vector revision pinned separately.",
    "Compare AEAD128 encrypt/decrypt outputs against official SP 800-232 known-answer vectors from ascon/ascon-c. Cover empty inputs, partial blocks and multi-block messages.",
    "Test wrong tags, modified ciphertext/associated data, reset during an operation and ready/valid backpressure. Check byte masks and authentication-valid handling.",
    "Add and verify the application plaintext buffer, including discard on failure; then test Hash256, XOF128 and CXOF128 separately before advertising them as runnable.",
    "Compare mapped-cell behavior with the RTL before adding IHP delay simulation. Functional equivalence does not establish resistance to physical attacks."
  ],
  "stages": [
    { "id": "rtl", "label": "RTL simulation", "status": "unavailable", "reason": "Source reference only. The browser RTL build and standardized known-answer tests are not yet integrated." },
    { "id": "synthesis", "label": "Synthesis", "status": "unavailable", "reason": "The configuration/includes and multi-file SystemVerilog path must be qualified before IHP mapping is enabled." },
    { "id": "timing", "label": "Cell timing", "status": "unavailable", "reason": "No AiSIC IHP mapping or qualified timing simulation is published for this core." }
  ],
  "qualification": { "status": "source-reference", "browserRunnable": false, "note": "Pinned upstream source links and an AiSIC teaching explanation only. No RTL bundle, cryptographic validation, simulation result, synthesized netlist or IHP area/delay is provided." },
  "references": [
    { "label": "Official Ascon implementations page (links this author repository)", "url": "https://ascon.isec.tugraz.at/implementations.html" },
    { "label": "NIST SP 800-232 final standard", "url": "https://csrc.nist.gov/pubs/sp/800/232/final" },
    { "label": "Official Ascon C reference and known-answer vectors", "url": "https://github.com/ascon/ascon-c" }
  ]
}
