Hyppää sisältöön
    • Suomeksi
    • In English
Trepo
  • Suomeksi
  • In English
  • Kirjaudu
Näytä viite 
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto
  • Näytä viite
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto
  • Näytä viite
JavaScript is disabled for your browser. Some features of this site may not work without it.

Optimizing Ascon-AEAD128 on RISC-V microcontrollers: an even-odd bit-interleaving assembly approach

Podder, Sourav (2026)

 
Avaa tiedosto
PodderSourav.pdf (3.685Mt)
Lataukset: 



Podder, Sourav
2026

Master's Programme in Computing Sciences and Electrical Engineering
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Hyväksymispäivämäärä
2026-06-05
Näytä kaikki kuvailutiedot
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202606046931
Tiivistelmä
In August 2025, NIST finalized Special Publication 800-232, standardizing the Ascon family of lightweight cryptographic algorithms for constrained devices. Ascon-AEAD128, the authenticated-encryption algorithm evaluated in this thesis, is built around a compact 320-bit permutation that uses Boolean operations and word rotations instead of lookup tables or modular arithmetic. On 32-bit RV32IMAC hardware such as the Espressif ESP32-C6, Ascon's 64-bit rotations must be synthesized from several 32-bit shift and combine instructions. This cost appears repeatedly inside the eight-round Ascon-p[8] permutation used during message processing and motivates the even-odd bit-interleaving approach studied in this work.
This thesis investigates Even-Odd (EO) bit interleaving as a practical optimization technique for Ascon-AEAD128 on the ESP32-C6. EO interleaving splits each 64-bit Ascon state word into two 32-bit halves: one containing all even-position bits and the other containing all odd-position bits. This representation changes each 64-bit rotation into two independent 32-bit rotations, reducing cross-word dependencies in the linear diffusion layer. The final implementation combines a hand-written RISC-V assembly permutation core, split byte-to-EO conversion macros, a fused standard-byte AEAD fast path for the measured benchmark shape, instruction-RAM placement for the hot assembly loop, and a 17-instruction rotated-output S-box network that restores the normal EO state mapping after every round. A native EO pipeline is also implemented as a non-standard measurement variant to isolate the cost of representation conversion.
The final EO assembly permutation achieves 950.32 cycles per P8 invocation on the physical ESP32-C6, improving on the optimized C baseline at 1304.51 cycles by 27.15 percent. At the inner-loop level, this corresponds to a static round-body count of 912 instructions per P8 (8 × 114 instructions per round), 4 instructions per round below the closest related hand-written RISC-V assembly result by Jellema, whose reported 118 cycles per round (944 cycles per P8 inner loop) correspond to approximately the same number of inner-loop instructions on the in-order RV32IMAC pipeline. To the best of our knowledge, this is the first reported Ascon-p[8] inner loop on RV32IMAC to drop below Jellema’s reported 944-cycle P8-equivalent inner-loop result at the static instruction-count level. At the complete standard byte-oriented AEAD interface, the final EO-ASM implementation reaches 77.92 cycles per byte for 1024-byte encryption and 78.18 cycles per byte for 1024-byte decryption. These results outperform the measured OPT32 C baseline at 79.97 and 79.44 cycles per byte respectively, answering the central practical question of the thesis positively. The native EO experiment reaches 65.09 cycles per byte at 1024 bytes, showing that representation conversion remains the main residual overhead even after the full optimization chain. All 81 edge-case correctness tests pass, the tag-tamper test rejects modified authentication tags, and the implementation is verified byte-for-byte against the official Ascon reference C implementation using fixed test inputs.
Kokoelmat
  • Opinnäytteet - ylempi korkeakoulututkinto [43034]
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste
 

 

Selaa kokoelmaa

TekijätNimekkeetTiedekunta (2019 -)Tiedekunta (- 2018)Tutkinto-ohjelmat ja opintosuunnatAvainsanatJulkaisuajatKokoelmat

Omat tiedot

Kirjaudu sisäänRekisteröidy
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste