NIST Lightweight Cryptography finalist using SKINNY-128-384 tweakable block cipher. Primary recommendation of Romulus family with 128-bit nonce and tag.
| Property | Value |
|---|---|
| Category | Authenticated Encryption |
| Sub-category | Authenticated Encryption |
| Security status | 🛡️ Secure |
| Complexity | Advanced |
| Inventor | Tetsu Iwata, Mustafa Khairallah, Kazuhiko Minematsu, Thomas Peyrin |
| Year | 2019 |
| Origin | 🇯🇵 Japan |
| Source | algorithms/aead/romulus.js |
| Parameter | Supported values |
|---|---|
| Tag sizes | 16 bytes (128 bits) |
| Flag | Value |
|---|---|
SupportsDetached |
No |
Status: 🛡️ Secure
No vulnerabilities are recorded for this implementation.
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — Romulus-N1 NIST KAT Count=1 (empty message, empty AD)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
nonce |
000102030405060708090a0b0c0d0e0f |
associatedData |
(empty) |
input |
(empty) |
expected |
5d8db25aacb3dab45fbc2f8d77849f90 |