1<!DOCTYPE html> 2<html lang="en"> 3<head> 4 <title>Keccak Team</title> 5 6 <base href="https://keccak.team/" /> 7 8 <meta charset="UTF-8"> 9 <meta name="viewport" content="width=device-width, initial-scale=1"> 10 <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no"> 11 12 <link rel="shortcut icon" href="assets/img/favicon.png" /> 13 14 <meta name="description" content=""> 15 16 <!-- CSS --> 17 <link rel="stylesheet" type="text/css" href="assets/css/preload.css"> 18 <link rel="stylesheet" type="text/css" href="fonts/fonts.css"> 19 <link rel="stylesheet" type="text/css" href="assets/css/vendors.css"> 20 <link rel="stylesheet" type="text/css" href="assets/css/style-blue.css" title="default"> 21 <link rel="stylesheet" type="text/css" href="assets/css/width-full.css" title="default"> 22 <link rel="stylesheet" type="text/css" href="assets/css/highlight/xcode.css"> 23 <link rel="stylesheet" type="text/css" href="assets/css/style.css"> 24 25 26 <!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries --> 27 <!--[if lt IE 9]> 28
28<script src="assets/js/html5shiv.min.js"></script>
28 29
29<script src="assets/js/respond.min.js"></script>
29 30 <![endif]--> 31 32
32<script type="text/x-mathjax-config"> 33 MathJax.Hub.Config({ 34 tex2jax: {inlineMath: [['$','$'], ['\\(','\\)']]} 35 }); 36 </script>
36 37</head> 38 39<!-- Preloader --> 40<div id="preloader"> 41 <div id="status"> </div> 42</div> 43 44<div class="sb-site-container"> 45<div class="boxed"> 46 47<header id="header-full-top" class="hidden-xs header-full"> 48 <nav class="top-nav"> 49 <ul class="top-nav-social hidden-sm"> 50 <li><a href="news.atom" class="animated fadeIn animation-delay-6 rss"><i class="fa fa-rss"></i></a></li> 51 <li><a href="https://twitter.com/KeccakTeam" class="animated fadeIn animation-delay-7 twitter"><i class="fa fa-twitter"></i></a></li> 52 <li><a href="https://github.com/KeccakTeam" class="animated fadeIn animation-delay-8 git"><i class="fa fa-github"></i></a></li> 53 </ul> 54 </nav> 55 <div class="container"> 56 <div class="header-full-title"> 57 <h1 class="animated fadeInRight"><a href="index.html">Team <span>Keccak</span></a></h1> 58 <p class="animated fadeInRight"> 59 Guido Bertoni<sup>3</sup>, Joan Daemen<sup>2</sup>, Seth Hoffert, Silvia Mella<sup>2</sup>, Michaël Peeters<sup>1</sup>, Gilles Van Assche<sup>1</sup> and Ronny Van Keer<sup>1</sup><br /> 60 <sup>1</sup><a href="http://www.st.com/">STMicroelectronics</a> - <sup>2</sup><a href="http://www.ru.nl/english/">Radboud University</a> - <sup>3</sup><a href="https://www.securitypattern.com/">Security Pattern</a> 61 </p> 62 </div> 63 </div> 64</header> <!-- header-full --> 65<nav class="navbar navbar-default navbar-header-full navbar-dark yamm navbar-static-top" role="navigation" id="header"> 66 <div class="container"> 67 <!-- Brand and toggle get grouped for better mobile display --> 68 <div class="navbar-header"> 69 <button type="button" class="navbar-toggle" data-toggle="collapse" data-target="#bs-example-navbar-collapse-1"> 70 <span class="sr-only">Toggle navigation</span> 71 <i class="fa fa-bars"></i> 72 </button> 73 <a id="ar-brand" class="navbar-brand hidden-lg hidden-md hidden-sm" href="index.html">Team <span>Keccak</span></a> 74 </div> <!-- navbar-header --> 75 <div class="collapse navbar-collapse" id="bs-example-navbar-collapse-1"> 76 <ul class="nav navbar-nav"> 77 <li><a href="index.html">Home</a></li> 78 <li class="dropdown"> 79 <a href="javascript:void(0);" class="dropdown-toggle" data-toggle="dropdown" data-hover="dropdown">Design</a> 80 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 81 <li class="dropdown-submenu"> 82 <a href="javascript:void(0);" class="has_children">Schemes</a> 83 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 84 <li><a href="keccak.html">Keccak</a></li> 85 <li><a href="ketje.html">Ketje</a></li> 86 <li><a href="keyak.html">Keyak</a></li> 87 <li><a href="kangarootwelve.html">KangarooTwelve</a></li> 88 <li><a href="turboshake.html">TurboSHAKE</a></li> 89 <li><a href="kravatte.html">Kravatte</a></li> 90 <li role="presentation" class="divider"></li> 91 <li><a href="xoofff.html">Xoofff</a></li> 92 <li><a href="xoodyak.html">Xoodyak</a></li> 93 </ul> 94 </li> 95 <li class="dropdown-submenu"> 96 <a href="javascript:void(0);" class="has_children">Constructions</a> 97 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 98 <li><a href="sponge_duplex.html">Sponge, duplex and variants</a></li> 99 <li><a href="farfalle.html">Farfalle</a></li> 100 </ul> 101 </li> 102 <li class="dropdown-submenu"> 103 <a href="javascript:void(0);" class="has_children">Permutations</a> 104 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 105 <li><a href="keccakp.html">Keccak-<i>p</i></a></li> 106 <li><a href="xoodoo.html">Xoodoo</a></li> 107 </ul> 108 </li> 109 </ul> 110 </li> 111 <li class="dropdown"> 112 <a href="javascript:void(0);" class="dropdown-toggle" data-toggle="dropdown" data-hover="dropdown">Analysis</a> 113 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 114 <li><a href="crunchy_contest.html">Crunchy contest</a></li> 115 <li><a href="ketje_contest.html">Ketje contest</a></li> 116 <li><a href="third_party.html">Third-party cryptanalysis</a></li> 117 </ul> 118 </li> 119 <li class="dropdown"> 120 <a href="javascript:void(0);" class="dropdown-toggle" data-toggle="dropdown" data-hover="dropdown">Implementation</a> 121 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 122 <li class="dropdown-submenu"> 123 <a href="javascript:void(0);" class="has_children">Software</a> 124 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 125 <li>
125<a href="software.html">Implementations</a></li> 126 <li><a href="sw_performance.html">Performance figures</a></li> 127 <li><a href="binaries.html">Binaries</a></li> 128 </ul> 129 </li> 130 <li><a href="hardware.html">Hardware</a></li> 131 </ul> 132 </li> 133 <li class="dropdown"> 134 <a href="javascript:void(0);" class="dropdown-toggle" data-toggle="dropdown" data-hover="dropdown">Documentation</a> 135 <ul class="dropdown-menu dropdown-menu-left animated-2x animated fadeIn"> 136 <li><a href="specifications.html">Specifications</a></li> 137 <li><a href="papers.html">Our papers</a></li> 138 <li><a href="third_party.html">Third-party cryptanalysis</a></li> 139 <li role="presentation" class="divider"></li> 140 <li><a href="figures.html">Figures</a></li> 141 <li><a href="glossary.html">Glossary</a></li> 142 <li role="presentation" class="divider"></li> 143 <li><a href="archives.html">Archives</a></li> 144 </ul> 145 </li> 146 147 <li><a href="team.html">About us</a></li> 148 149 </ul> 150 </div><!-- navbar-collapse --> 151 </div><!-- container --> 152</nav> 153 154<header class="main-header"> 155<div class="container"> 156<h1 class="page-title">The <span class='sc'>Keyak</span> authenticated encryption scheme</h1> 157</div> 158</header> 159<div class="container"> 160<div class="panel panel-default"> 161<div class="panel-body"> 162<p><span class="sc">Keyak</span> is an authenticated encryption scheme based on <span class='sc'>Keccak</span>-<i>p</i>. It takes as input a *secret and unique value* (SUV), then some associated data (or metadata) that are authenticated but not encrypted and finally some plaintext. It produces a cryptogram comprising the ciphertext and a tag authenticating both the metadata and the plaintext. The recipient holding the same secret key can decrypt the cryptogram and check whether it is authentic.</p> 163 164<p><span class="sc">Keyak</span> supports also the concept of sessions. Without having to input the key again and a new nonce, the communicating parties can keep on exchanging metadata-plaintext pairs. Each time, the tag authenticates the complete exchange of messages so far. The SUV can be either a secret key and a nonce, or a one-time session key derived using public-key cryptographic techniques.</p> 165 166<p><span class="sc">Keyak</span> provides strong bounds against generic attacks and uses the well-analyzed <span class='sc'>Keccak</span>-<i>p</i> permutation. It aims at robustness and performance on a wide range of processors.</p> 167</div> 168</div> 169 170<h1>Technical details</h1> 171 172<table class="table table-bordered"> 173<tr class="active"><th>Synopsis</th><th>The <span class='sc'>Keyak</span> authenticated encryption scheme</th></tr> 174 <tr><th>Designed by</th><td>Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche and Ronny Van Keer</td></tr> 175 <tr><th>Implements</th><td>An authenticated encryption scheme with associated data and support for sessions</td></tr> 176 <tr><th>Construction</th><td>The <span class="sc">Motorist</span> authenticated encryption mode on top of the full-state keyed duplex construction</td></tr> 177 <tr><th>Primitive</th><td>The <span class='sc'>Keccak</span>-<i>p</i>[800, 12] permutation (for <span class="sc">River Keyak</span>) or the <span class='sc'>Keccak</span>-<i>p</i>[1600, 12] permutation (for the other instances)</td></tr> 178 <tr><th>Parameterized by</th><td>The width of the permutation <i>b</i> and by the degree of parallelism Π</tr> 179 <tr><th>Instances</th><td><table class="table"> 180 <thead><tr><th>Instance</th><th>width</th><th>degree of parallelism</th></tr></thead> 181 <tbody> 182<tr><td><span class="sc">River Keyak</span></td><td><i>b</i>=800</td><td>Π=1</td></tr> 183<tr><td><span class="sc">Lake Keyak</span></td><td><i>b</i>=1600</td><td>Π=1</td></tr> 184<tr><td><span class="sc">Sea Keyak</span></td><td><i>b</i>=1600</td><td>
184Î =2</td></tr> 185<tr><td><span class="sc">Ocean Keyak</span></td><td><i>b</i>=1600</td><td>Î =4</td></tr> 186<tr><td><span class="sc">Lunar Keyak</span></td><td><i>b</i>=1600</td><td>Î =8</td></tr> 187</tbody> 188 </table></td></tr> 189 <tr><th>Status</th><td class="success">Third-round candidate in the CAESAR competition</td></tr> 190</table> 191 192<p>We define and document <span class='sc'>Keyak</span> in the <a href="files/Keyakv2-doc2.2.pdf">Keyak CAESAR submission v2.2</a>.</p> 193<p>The reference implementation of <span class='sc'>Keyak</span> v2 is part of <a href="https://github.com/KeccakTeam/KeccakTools"><span class='sc'>Keccak</span> Tools</a>. Further implementations can be found in the <a href="https://github.com/XKCP/XKCP"><span class='sc'>Keccak</span> Code Package</a>.</p></div> 194<footer id="footer"> 195 Unless otherwise specified, the contents and files within the domain keccak.team are © 2008-2026 196 <a href="team.html">Guido Bertoni, Joan Daemen, Seth Hoffert, Silvia Mella, Michaël Peeters, Gilles Van Assche and Ronny Van Keer</a>. 197 <br/> 198 Webmaster: <a href="http://viguier.nl">Benoit Viguier</a>. 199</footer> 200 201</div> <!-- boxed --> 202</div> <!-- sb-site --> 203 204<div id="back-top"> 205 <a href="#header"><i class="fa fa-chevron-up"></i></a> 206</div> 207 208<!-- Scripts --> 209<!-- Compiled in vendors.js --> 210<!--
211<script src="assets/js/jquery.min.js"></script>
vendor: 1 bytes, line 211
211
212<script src="assets/js/jquery.cookie.js"></script>
vendor: 1 bytes, line 212
212
213<script src="assets/js/imagesloaded.pkgd.min.js"></script>
vendor: 1 bytes, line 213
213
214<script src="assets/js/bootstrap.min.js"></script>
vendor: 1 bytes, line 214
214
215<script src="assets/js/bootstrap-switch.min.js"></script>
vendor: 1 bytes, line 215
215
216<script src="assets/js/wow.min.js"></script>
vendor: 1 bytes, line 216
216
217<script src="assets/js/slidebars.min.js"></script>
vendor: 1 bytes, line 217
217
218<script src="assets/js/jquery.bxslider.min.js"></script>
vendor: 1 bytes, line 218
218
219<script src="assets/js/holder.js"></script>
vendor: 1 bytes, line 219
219
220<script src="assets/js/buttons.js"></script>
vendor: 1 bytes, line 220
220
221<script src="assets/js/jquery.mixitup.min.js"></script>
vendor: 1 bytes, line 221
221
222<script src="assets/js/circles.min.js"></script>
vendor: 1 bytes, line 222
222
223<script src="assets/js/masonry.pkgd.min.js"></script>
vendor: 1 bytes, line 223
223
224<script src="assets/js/jquery.matchHeight-min.js"></script>
224 225--> 226
227<script src="assets/js/vendors.js"></script>
227 228 229<!--
229<script type="text/javascript" src="assets/js/jquery.themepunch.tools.min.js?rev=5.0"></script>
vendor: 1 bytes, line 229
229
230<script type="text/javascript" src="assets/js/jquery.themepunch.revolution.min.js?rev=5.0"></script>
230--> 231
232<script src="assets/js/DropdownHover.js"></script>
vendor: 1 bytes, line 232
232
233<script src="assets/js/app.js"></script>
vendor: 1 bytes, line 233
233
234<script src="assets/js/holder.js"></script>
vendor: 1 bytes, line 234
234
235<script src="assets/js/home_info.js"></script>
vendor: 1 bytes, line 235
235
236<script src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.0/MathJax.js?config=TeX-AMS-MML_HTMLorMML"></script>
vendor: 1 bytes, line 236
236
237<script src="asset/css/highlight/highlight.pack.js"></script>
vendor: 1 bytes, line 237
237
238<script> 239hljs.configure({ 240 languages: ['python'] 241}) 242 243hljs.initHighlightingOnLoad(); 244</script>
244 245 246</body> 247 248</html>
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.