High-performance authenticated encryption with associated data (AEAD) using AES round function. Winner of CAESAR competition high-performance category with exceptional speed on AES-NI enabled processors.
| Property | Value |
|---|---|
| Category | Stream Ciphers |
| Sub-category | AEAD Stream Cipher |
| Security status | 🎓 Educational Only |
| Complexity | Advanced |
| Inventor | Hongjun Wu, Bart Preneel |
| Year | 2016 |
| Origin | Not specified |
| Source | algorithms/stream/aegis-128.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 16 bytes (128 bits) |
| Nonce sizes | 16 bytes (128 bits) |
Status: 🎓 Educational Only
| Issue | Description | Mitigation |
|---|---|---|
| Side-Channel Attacks | Potential timing vulnerabilities in AES round function implementations without hardware acceleration | — |
2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — AEGIS-128 Test Vector 1 (Educational)
Source: Educational implementation test
| Field | Value |
|---|---|
key |
10010000000000000000000000000000 |
iv |
10000200000000000000000000000000 |
input |
000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f |
expected |
0001020000000000000000000000000000010200000000000000000000000000 |
Vector 2 — AEGIS-128 Test Vector 2 (Shorter input)
Source: Educational implementation test
| Field | Value |
|---|---|
key |
10010000000000000000000000000000 |
iv |
10000200000000000000000000000000 |
input |
000102030405060708090a0b0c0d0e0f |
expected |
00010200000000000000000000000000 |