Elephant AEAD variant using Keccak-p[200] permutation with 18 rounds and 128-bit tag. NIST Lightweight Cryptography finalist with highest security level.
| Property | Value |
|---|---|
| Category | Authenticated Encryption |
| Sub-category | Authenticated Encryption |
| Security status | Not classified |
| Complexity | Advanced |
| Inventor | Tim Beyne, Yu Long Chen, Christoph Dobraunig, Bart Mennink |
| Year | 2019 |
| Origin | 🇧🇪 Belgium |
| Source | algorithms/aead/elephant.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 16 bytes (128 bits) |
| Tag sizes | 16 bytes (128 bits) |
| Flag | Value |
|---|---|
SupportsDetached |
No |
Status: not classified — treat as unverified.
No vulnerabilities are recorded for this implementation.
2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — NIST LWC KAT Vector #1 (empty PT, empty AD)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b |
associatedData |
(empty) |
input |
(empty) |
expected |
48bf257607d09ebe1c0e108b91058877 |
Vector 2 — NIST LWC KAT Vector #2 (empty PT, 1-byte AD)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b |
associatedData |
00 |
input |
(empty) |
expected |
6e3705abdc45250ceeb36e4d991b741d |