Lightweight authenticated encryption for extremely constrained devices. Uses 200-bit Keccak-p permutation with 96-bit key and 16-byte rate.
| Property | Value |
|---|---|
| Category | Authenticated Encryption |
| Sub-category | Authenticated Encryption |
| Variant | jr |
| Security status | Not classified |
| Complexity | Advanced |
| Inventor | Guido Bertoni, Joan Daemen, Michaël Peeters, Gilles Van Assche, Ronny Van Keer |
| Year | 2016 |
| Origin | 🌐 International |
| Source | algorithms/aead/ketje.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 12 bytes (96 bits) |
| Tag sizes | 16 bytes (128 bits) |
| Flag | Value |
|---|---|
SupportsDetached |
No |
Status: not classified — treat as unverified.
No vulnerabilities are recorded for this implementation.
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — Ketje Jr: Empty message
| Field | Value |
|---|---|
key |
000102030405060708090a0b |
nonce |
101112131415161718191a |
aad |
(empty) |
input |
(empty) |
expected |
8863d23f545aa267efed5d57a0ff001c |
Vector 2 — Ketje Jr: 16-byte plaintext
| Field | Value |
|---|---|
key |
000102030405060708090a0b |
nonce |
101112131415161718191a |
aad |
(empty) |
input |
00112233445566778899aabbccddeeff |
expected |
876139e1b2ac4db54db9393bcecd08c1995151a728881be914bad2d245e93c0f |
Vector 3 — Ketje Jr: 15-byte plaintext with 14-byte AAD
| Field | Value |
|---|---|
key |
000102030405060708090a0b |
nonce |
101112131415161718191a |
aad |
6164646974696f6e616c2064617461 |
input |
746865207365637265742074657874 |
expected |
72199bac3edf79c25394dfc3e2dbb3c4c382d6e6c5f2ca57c3c4cc32b31e3e |