Software implementation of the NSA’s ARADI block cipher on Arm Cortex–M4
Resumo
ARADI is a block cipher proposed by the NSA for inline memory encryption and paired with LLAMA, an authenticated-encryption mode for low-latency memory protection. This work evaluates the software viability of the NSA’s ARADI block cipher on a 32-bit Arm Cortex–M4 microcontroller. We derive an optimized linear map and a shuffle-based two-block formulation that leverages packed halfword parallelism. Our optimized implementation achieves a 2.36× performance improvement over the two-block NSA baseline. Finally, we provide comparative benchmarks against ChaCha–Poly1305 and AES-256.Referências
Adomnicai, A. and Peyrin, T. (2020). Fixslicing AES-like ciphers: New bitsliced AES speed records on ARM-Cortex M and RISC-V. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021(1):402–425.
Almeida, J. B., Barbosa, M., Barthe, G., Dupressoir, F., and Emmi, M. (2016). Verifying constant-time implementations. In 25th USENIX Security Symposium, pages 53–70.
Avanzi, R., Dunkelman, O., and Ghosh, S. (2024). A note on ARADI and LLAMA. Cryptology ePrint Archive, Paper 2024/1328.
Bellini, E., Formenti, M., Gérault, D., Grados, J., Hambitzer, A., Huang, Y. J., Huynh, P., Rachidi, M., Rohit, R., and Tiwari, S. K. (2024). CLAASPing ARADI: Automated analysis of the ARADI block cipher. In Progress in Cryptology – INDOCRYPT 2024, volume 15496 of Lecture Notes in Computer Science, pages 90–113. Springer, Cham.
Black, J. and Rogaway, P. (2002). A suggestion for handling arbitrary-length messages with a single-key MAC. In Fast Software Encryption – FSE 2002, volume 2365 of LNCS, pages 81–105. Springer.
Borghoff, J. et al. (2012). PRINCE – a low-latency block cipher for pervasive computing applications. In ASIACRYPT 2012, volume 7658 of Lecture Notes in Computer Science, pages 208–225. Springer.
Dunkelman, O. and Ghosh, S. (2025). Improved Key-Recovery Attacks on ARADI up to 12 Rounds Using ZeroSum and the Fast Hadamard Transform. Cryptology ePrint Archive, Paper 2025/1227.
Ghosh, S., Michel, B., and Naya-Plasencia, M. (2025). Differential-MITM attack on 14-round ARADI. Cryptology ePrint Archive, Paper 2025/1918.
Greene, P., Motley, M., and Weeks, B. (2024). ARADI and LLAMA: Low-Latency Cryptography for Memory Encryption. Cryptology ePrint Archive, Paper 2024/1240.
Halderman, J. A. et al. (2008). Lest we remember: Cold boot attacks on encryption keys. In 17th USENIX Security Symposium, pages 45–60.
Hülsing, A., Rijneveld, J., and Schwabe, P. (2016a). ARMed SPHINCS – Computing a 41KB Signature in 16KB of RAM. In Persiano, G. and Yang, B.-Y., editors, Public Key Cryptography – PKC 2016, volume 9614 of Lecture Notes in Computer Science, pages 446–470. Springer-Verlag Berlin Heidelberg.
Hülsing, A., Rijneveld, J., and Schwabe, P. (2016b). ARMed SPHINCS code package. [link]. ChaCha12/20 Arm code package.
La Scala, R. and Tiwari, S. K. (2026). Oracle-based multistep strategy for solving polynomial systems over finite fields and algebraic cryptanalysis of the ARADI cipher. Advances in Mathematics of Communications, 23:255–273.
Leander, G., Moos, T., Moradi, A., and Rasoolzadeh, S. (2021). The SPEEDY family of block ciphers: Engineering an ultra low-latency cipher from gate level for secure processor architectures. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021(4):510–545.
Mandal, S., Mondal, S. K., Rohit, R., and Sarkar, S. (2025). Improved differential cryptanalysis of ARADI. Cryptology ePrint Archive, Paper 2025/1976.
Markettos, A. T. et al. (2019). Thunderclap: Exploring vulnerabilities in operating system IOMMU protection via DMA from untrustworthy peripherals. In NDSS Symposium.
Moon, A. (2014). poly1305-donna. [link].
Nir, Y. and Langley, A. (2018). ChaCha20 and Poly1305 for IETF Protocols. RFC 8439.
Warren, Jr., H. S. (2013). Hacker’s Delight. Addison-Wesley, 2nd edition.
Almeida, J. B., Barbosa, M., Barthe, G., Dupressoir, F., and Emmi, M. (2016). Verifying constant-time implementations. In 25th USENIX Security Symposium, pages 53–70.
Avanzi, R., Dunkelman, O., and Ghosh, S. (2024). A note on ARADI and LLAMA. Cryptology ePrint Archive, Paper 2024/1328.
Bellini, E., Formenti, M., Gérault, D., Grados, J., Hambitzer, A., Huang, Y. J., Huynh, P., Rachidi, M., Rohit, R., and Tiwari, S. K. (2024). CLAASPing ARADI: Automated analysis of the ARADI block cipher. In Progress in Cryptology – INDOCRYPT 2024, volume 15496 of Lecture Notes in Computer Science, pages 90–113. Springer, Cham.
Black, J. and Rogaway, P. (2002). A suggestion for handling arbitrary-length messages with a single-key MAC. In Fast Software Encryption – FSE 2002, volume 2365 of LNCS, pages 81–105. Springer.
Borghoff, J. et al. (2012). PRINCE – a low-latency block cipher for pervasive computing applications. In ASIACRYPT 2012, volume 7658 of Lecture Notes in Computer Science, pages 208–225. Springer.
Dunkelman, O. and Ghosh, S. (2025). Improved Key-Recovery Attacks on ARADI up to 12 Rounds Using ZeroSum and the Fast Hadamard Transform. Cryptology ePrint Archive, Paper 2025/1227.
Ghosh, S., Michel, B., and Naya-Plasencia, M. (2025). Differential-MITM attack on 14-round ARADI. Cryptology ePrint Archive, Paper 2025/1918.
Greene, P., Motley, M., and Weeks, B. (2024). ARADI and LLAMA: Low-Latency Cryptography for Memory Encryption. Cryptology ePrint Archive, Paper 2024/1240.
Halderman, J. A. et al. (2008). Lest we remember: Cold boot attacks on encryption keys. In 17th USENIX Security Symposium, pages 45–60.
Hülsing, A., Rijneveld, J., and Schwabe, P. (2016a). ARMed SPHINCS – Computing a 41KB Signature in 16KB of RAM. In Persiano, G. and Yang, B.-Y., editors, Public Key Cryptography – PKC 2016, volume 9614 of Lecture Notes in Computer Science, pages 446–470. Springer-Verlag Berlin Heidelberg.
Hülsing, A., Rijneveld, J., and Schwabe, P. (2016b). ARMed SPHINCS code package. [link]. ChaCha12/20 Arm code package.
La Scala, R. and Tiwari, S. K. (2026). Oracle-based multistep strategy for solving polynomial systems over finite fields and algebraic cryptanalysis of the ARADI cipher. Advances in Mathematics of Communications, 23:255–273.
Leander, G., Moos, T., Moradi, A., and Rasoolzadeh, S. (2021). The SPEEDY family of block ciphers: Engineering an ultra low-latency cipher from gate level for secure processor architectures. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2021(4):510–545.
Mandal, S., Mondal, S. K., Rohit, R., and Sarkar, S. (2025). Improved differential cryptanalysis of ARADI. Cryptology ePrint Archive, Paper 2025/1976.
Markettos, A. T. et al. (2019). Thunderclap: Exploring vulnerabilities in operating system IOMMU protection via DMA from untrustworthy peripherals. In NDSS Symposium.
Moon, A. (2014). poly1305-donna. [link].
Nir, Y. and Langley, A. (2018). ChaCha20 and Poly1305 for IETF Protocols. RFC 8439.
Warren, Jr., H. S. (2013). Hacker’s Delight. Addison-Wesley, 2nd edition.
Publicado
01/09/2026
Como Citar
RABELO, José Eduardo Santos; LÓPEZ, Julio.
Software implementation of the NSA’s ARADI block cipher on Arm Cortex–M4. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 1443-1449.
DOI: https://doi.org/10.5753/sbseg.2026.29334.
