ACORN-128
Production-grade authenticated encryption with associated data (AEAD) stream cipher. CAESAR competition winner for lightweight cryptography with 128-bit security and efficient implementation.
Properties
| Property |
Value |
| Category |
Stream Ciphers |
| Sub-category |
AEAD Stream Cipher |
| Security status |
🛡️ Secure |
| Complexity |
Intermediate |
| Inventor |
Hongjun Wu, Tao Huang, Phuong Pham, Steven Sim |
| Year |
2016 |
| Origin |
Not specified |
| Source |
algorithms/stream/acorn.js |
Parameters
| Parameter |
Supported values |
| Key sizes |
16 bytes (128 bits) |
| Nonce sizes |
16 bytes (128 bits) |
| Tag sizes |
8 bytes (64 bits) to 16 bytes (128 bits) |
Capabilities
| Flag |
Value |
SupportsDetached |
No |
Security
Status: 🛡️ Secure
Known vulnerabilities
| Issue |
Description |
Mitigation |
| Implementation Attacks |
Side-channel vulnerabilities in software implementations without proper countermeasures |
Use constant-time implementation and appropriate side-channel protection |
| Weak Key Classes |
Very small subset of keys may have slightly reduced security margins (theoretical) |
Use proper random key generation - no practical impact for random keys |
Documentation
References
Test vectors
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — CAESAR ACORN-128 Test Vector 1 (Empty Message)
| Field |
Value |
key |
00000000000000000000000000000000 |
iv |
00000000000000000000000000000000 |
aad |
(empty) |
input |
(empty) |
expected |
835e5317896e86b2447143c74f6ffc1e |
Vector 2 — CAESAR ACORN-128 Test Vector 2 (Single Byte)
| Field |
Value |
key |
00000000000000000000000000000000 |
iv |
00000000000000000000000000000000 |
aad |
(empty) |
input |
01 |
expected |
2b4b60640e26f0a99dd01f93bf634997cb |
Vector 3 — CAESAR ACORN-128 Test Vector 3 (AAD Only)
| Field |
Value |
key |
00000000000000000000000000000000 |
iv |
00000000000000000000000000000000 |
aad |
01 |
input |
(empty) |
expected |
982ef7d1bba7f89a1575297a095cd7f2 |
← All algorithms