NIST’s lightweight cryptography standard for authenticated encryption. Uses 128-bit keys with 8-byte rate for balanced security and performance.
| Property | Value |
|---|---|
| Category | Authenticated Encryption |
| Sub-category | Lightweight Cryptography |
| Variant | ascon128 |
| Security status | 🛡️ Secure |
| Complexity | Intermediate |
| Inventor | Christoph Dobraunig, Maria Eichlseder, Florian Mendel, Martin Schläffer |
| Year | 2023 |
| Origin | Not specified |
| Source | algorithms/aead/ascon.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 16 bytes (128 bits) |
| Tag sizes | 16 bytes (128 bits) |
| Flag | Value |
|---|---|
SupportsDetached |
No |
Status: 🛡️ Secure
No vulnerabilities are recorded for this implementation.
4 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — Ascon-128: Empty message, empty AAD (Count 1)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b0c0d0e0f |
aad |
(empty) |
input |
(empty) |
expected |
e355159f292911f794cb1432a0103a8a |
Vector 2 — Ascon-128: Single byte plaintext (Count 34)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b0c0d0e0f |
aad |
(empty) |
input |
00 |
expected |
bc18c3f4e39eca7222490d967c79bffc92 |
Vector 3 — Ascon-128: 8-byte plaintext (Count 265)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b0c0d0e0f |
aad |
(empty) |
input |
0001020304050607 |
expected |
bc820dbdf7a4631c01a8807a44254b42ac6bb490da1e000a |
Vector 4 — Ascon-128: 16-byte plaintext with 8-byte AAD (Count 537)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b0c0d0e0f |
aad |
0001020304050607 |
input |
000102030405060708090a0b0c0d0e0f |
expected |
69ffee6f5505a4897e2ec80cbdff67ce31614dac97643c45940a8f9e7964613a |