Title: On the Scope of Lightweight Cryptography
Abstract: We survey the state of the art of lightweight symmetric crypto both in the literature and as used in actual protocols and standards. We also describe some of the attacks ran against these algorithms. Using the results of these surveys, we argue that "lightweight crypto" should be split into two concepts:
- "ultra-lightweight crypto" which targets the least powerful dedicated circuits and for which bold trade-offs make sense, and
- "pervasive crypto" which has less stringent efficiency requirements but which requires more conservative security margins and has to greatly emphasize the importance of SCA resistance.