{"catalogVersion":"symmetric-aead-dossier-v3-atomic-contributions","constructions":[{"adaptive_security":null,"api_style":null,"associated_data":"no","assumption_family":"symmetric cryptanalysis","assumption_id":"SYM-ASSUMPTION-HISTORICAL-DES-BLOCK-CIPHER-SECURITY","assumption_name":"historical DES block-cipher security","authors":["National Bureau of Standards"],"base_signature":null,"block_size":"64 bits","bootstrapping":null,"capabilities":["block-permutation"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"feistel","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-1977-DES","identifiable_abort":null,"key_size":"56-bit effective key","large_universe":null,"misuse_resistance":"not applicable; mode-defined","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"not applicable to the primitive","nonce_size":"not applicable","normative_status":"withdrawn and superseded; historical only","object_type":"block_cipher","online":"one block at a time","output_compatibility":null,"packing":null,"paper_title":"Data Encryption Standard","paper_url":"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub46.pdf","parallelizable":"independent block calls","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"symmetric_block_cipher","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"primitive","security_model":"concrete cryptanalysis","security_notion":"block-cipher pseudorandomness target","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"block":"64 bits","key":"56 effective bits"},"statefulness":null,"summary":"DES is included only to explain the standardization transition to AES.","supported_gates":null,"tag_size":"not applicable","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-1977-DES","year":1977},{"adaptive_security":null,"api_style":null,"associated_data":"no","assumption_family":"symmetric cryptanalysis","assumption_id":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","assumption_name":"AES pseudorandom-permutation security","authors":["National Institute of Standards and Technology"],"base_signature":null,"block_size":"128 bits","bootstrapping":null,"capabilities":["block-permutation","standardized-primitive"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"substitution_permutation_network","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2001-AES","identifiable_abort":null,"key_size":"128 / 192 / 256 bits","large_universe":null,"misuse_resistance":"not applicable; mode-defined","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"not applicable to the primitive","nonce_size":"not applicable","normative_status":"FIPS 197","object_type":"block_cipher","online":"one block at a time","output_compatibility":null,"packing":null,"paper_title":"Advanced Encryption Standard (AES)","paper_url":"https://csrc.nist.gov/pubs/fips/197/final","parallelizable":"independent block calls","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"symmetric_block_cipher","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"primitive","security_model":"concrete cryptanalysis","security_notion":"block-cipher PRP target","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"block":"128 bits","key":"128 / 192 / 256 bits"},"statefulness":null,"summary":"AES is a primitive. Confidentiality and authentication properties depend on the mode that uses it.","supported_gates":null,"tag_size":"not applicable","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2001-AES","year":2001},{"adaptive_security":null,"api_style":null,"associated_data":"no","assumption_family":"symmetric","assumption_id":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","assumption_name":"AES pseudorandom-permutation security","authors":["Morris Dworkin"],"base_signature":null,"block_size":"128-bit data blocks; padding, when needed, is outside the mode specification","bootstrapping":null,"capabilities":["variable-length-confidentiality"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"cipher_block_chaining","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2001-AESCBC","identifiable_abort":null,"key_size":"AES key size","large_universe":null,"misuse_resistance":"no; IV failure can reveal relations and the mode provides no integrity","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"unpredictable 128-bit IV for encryption","nonce_size":"128-bit IV","normative_status":"NIST SP 800-38A; confidentiality only","object_type":"confidentiality_mode","online":"encryption is sequential","output_compatibility":null,"packing":null,"paper_title":"Recommendation for Block Cipher Modes of Operation — Methods and Techniques","paper_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","parallelizable":"encryption no; decryption block calls yes","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"symmetric_encryption_mode","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"secret-key encryption","security_model":"block-cipher mode","security_notion":"confidentiality with proper randomized IV handling","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"iv":"128 bits","key":"AES key","tag":"none"},"statefulness":null,"summary":"CBC does not authenticate ciphertext. Padding and composition rules are outside this row.","supported_gates":null,"tag_size":"none","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2001-SP80038A","year":2001},{"adaptive_security":null,"api_style":null,"associated_data":"no","assumption_family":"symmetric","assumption_id":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","assumption_name":"AES pseudorandom-permutation security","authors":["Morris Dworkin"],"base_signature":null,"block_size":"byte/bit stream derived from 128-bit blocks","bootstrapping":null,"capabilities":["random-access-confidentiality","parallel-block-processing"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"counter_mode","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2001-AESCTR","identifiable_abort":null,"key_size":"AES key size","large_universe":null,"misuse_resistance":"no; keystream reuse exposes plaintext relations","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"counter blocks must be unique under a key","nonce_size":"profile-defined counter block totaling 128 bits","normative_status":"NIST SP 800-38A; confidentiality only","object_type":"confidentiality_mode","online":"yes","output_compatibility":null,"packing":null,"paper_title":"Recommendation for Block Cipher Modes of Operation — Methods and Techniques","paper_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","parallelizable":"yes","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"symmetric_encryption_mode","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"secret-key encryption","security_model":"block-cipher mode","security_notion":"confidentiality under unique counters","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"counter_block":"128 bits","key":"AES key","tag":"none"},"statefulness":null,"summary":"CTR is a confidentiality component used inside several AEAD constructions; it provides no integrity by itself.","supported_gates":null,"tag_size":"none","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2001-SP80038A","year":2001},{"adaptive_security":null,"api_style":null,"associated_data":"yes","assumption_family":"symmetric","assumption_id":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","assumption_name":"AES pseudorandom-permutation security","authors":["Morris Dworkin"],"base_signature":null,"block_size":"128-bit AES blocks","bootstrapping":null,"capabilities":["confidentiality","integrity","associated-data"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"ctr_plus_cbc_mac","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2004-CCM","identifiable_abort":null,"key_size":"AES key size","large_universe":null,"misuse_resistance":"no; nonce repetition violates the security contract","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"nonce must be unique under a key","nonce_size":"56–104 bits (7–13 octets)","normative_status":"NIST SP 800-38C","object_type":"AEAD","online":"no; CBC-MAC and message length precede CTR encryption","output_compatibility":null,"packing":null,"paper_title":"Recommendation for Block Cipher Modes of Operation — The CCM Mode for Authentication and Confidentiality","paper_url":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","parallelizable":"CTR portion yes; CBC-MAC portion no","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"authenticated_encryption","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"nonce-based AEAD","security_model":"composed block-cipher modes","security_notion":"authenticated encryption with associated data","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"AES key","nonce":"7–13 octets","tag":"4–16 octets subject to profile"},"statefulness":null,"summary":"CCM combines two sequential views of the message and is not a one-pass online AEAD.","supported_gates":null,"tag_size":"32–128 bits in permitted even-byte increments","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2004-CCM","year":2004},{"adaptive_security":null,"api_style":null,"associated_data":"yes","assumption_family":"symmetric","assumption_id":"SYM-ASSUMPTION-AES-PRP-PLUS-UNIVERSAL-HASH-BOUNDS","assumption_name":"AES PRP plus universal-hash bounds","authors":["Morris Dworkin"],"base_signature":null,"block_size":"128-bit AES and GHASH blocks","bootstrapping":null,"capabilities":["confidentiality","integrity","associated-data","parallel-processing"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"counter_plus_galois_hash","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2007-GCM","identifiable_abort":null,"key_size":"AES key size","large_universe":null,"misuse_resistance":"no; repeated IVs can catastrophically damage confidentiality and authentication","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"IV uniqueness is critical; 96 bits is the recommended interoperable length","nonce_size":"96 bits recommended; other lengths are processed by GHASH","normative_status":"NIST SP 800-38D","object_type":"AEAD","online":"yes","output_compatibility":null,"packing":null,"paper_title":"Recommendation for Block Cipher Modes of Operation — Galois/Counter Mode (GCM) and GMAC","paper_url":"https://csrc.nist.gov/pubs/sp/800/38/d/final","parallelizable":"yes for CTR and GHASH evaluation strategies","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"authenticated_encryption","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"nonce-based AEAD","security_model":"counter mode plus polynomial authentication","security_notion":"authenticated encryption with associated data","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"AES key","nonce":"96 bits recommended","tag":"up to 128 bits"},"statefulness":null,"summary":"The row makes nonce uniqueness prominent because GCM’s failure mode under reuse is a defining deployment constraint.","supported_gates":null,"tag_size":"profile-selected up to 128 bits with NIST constraints","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2007-GCM","year":2007},{"adaptive_security":null,"api_style":null,"associated_data":"yes; vector of associated-data strings","assumption_family":"symmetric","assumption_id":"SYM-ASSUMPTION-AES-CMAC-PRF-AND-AES-CTR-SECURITY","assumption_name":"AES-CMAC PRF and AES-CTR security","authors":["Dan Harkins"],"base_signature":null,"block_size":"128-bit AES blocks","bootstrapping":null,"capabilities":["nonce-misuse-resistance","deterministic-aead","associated-data-vector"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"synthetic_iv","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2008-AESSIV","identifiable_abort":null,"key_size":"256 / 384 / 512 bits split across S2V and CTR","large_universe":null,"misuse_resistance":"yes; repeated inputs reveal equality but do not cause GCM-style key recovery","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"optional; uniqueness improves privacy but repetition is tolerated with bounded leakage","nonce_size":"optional associated-data component; 128-bit random nonce recommended when used","normative_status":"RFC 5297 (Informational)","object_type":"misuse_resistant_AEAD","online":"no; synthetic IV is computed before CTR encryption","output_compatibility":null,"packing":null,"paper_title":"Synthetic Initialization Vector (SIV) Authenticated Encryption Using AES","paper_url":"https://www.rfc-editor.org/rfc/rfc5297.html","parallelizable":"CTR phase yes; S2V/CMAC chain limited","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"authenticated_encryption","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"synthetic-IV AEAD","security_model":"S2V plus CTR","security_notion":"deterministic/misuse-resistant authenticated encryption","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"256 / 384 / 512 bits","nonce":"optional","tag":"128 bits"},"statefulness":null,"summary":"“Misuse resistant” is not “misuse proof”: deterministic equality leakage and usage limits remain.","supported_gates":null,"tag_size":"128-bit synthetic IV","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2008-SIV","year":2008},{"adaptive_security":null,"api_style":null,"associated_data":"no","assumption_family":"symmetric cryptanalysis","assumption_id":"SYM-ASSUMPTION-CHACHA-ARX-STREAM-CIPHER-SECURITY","assumption_name":"ChaCha ARX stream-cipher security","authors":["Daniel J. Bernstein"],"base_signature":null,"block_size":"512-bit keystream blocks","bootstrapping":null,"capabilities":["software-oriented-stream-encryption","random-access-keystream"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"arx","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2008-CHACHA","identifiable_abort":null,"key_size":"256 bits in the primary profile","large_universe":null,"misuse_resistance":"no; repeated keystream exposes plaintext relations","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"nonce/counter input must not repeat under a key","nonce_size":"64 bits in the original family presentation","normative_status":"research construction; RFC 8439 defines the IETF ChaCha20 profile","object_type":"stream_cipher","online":"yes","output_compatibility":null,"packing":null,"paper_title":"ChaCha, a Variant of Salsa20","paper_url":"https://cr.yp.to/chacha/chacha-20080128.pdf","parallelizable":"block-function calls can be parallelized","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"symmetric_stream_cipher","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"stream cipher","security_model":"concrete cryptanalysis","security_notion":"pseudorandom keystream target","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"256 bits","keystream_block":"512 bits","nonce":"64 bits in original profile"},"statefulness":null,"summary":"The original family and the later 96-bit-nonce IETF profile are kept as distinct rows.","supported_gates":null,"tag_size":"none","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"SYM-PAPER-2008-CHACHA","year":2008},{"adaptive_security":null,"api_style":null,"associated_data":"yes","assumption_family":"symmetric composition","assumption_id":"SYM-ASSUMPTION-CHACHA20-STREAM-SECURITY-PLUS-POLY1305-ONE-TIME-AUTHENTICATION","assumption_name":"ChaCha20 stream security plus Poly1305 one-time authentication","authors":["Yoav Nir","Adam Langley"],"base_signature":null,"block_size":"512-bit ChaCha20 blocks; 16-byte Poly1305 processing","bootstrapping":null,"capabilities":["confidentiality","integrity","associated-data","software-portability"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"stream_cipher_plus_one_time_mac","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","identifiable_abort":null,"key_size":"256 bits","large_universe":null,"misuse_resistance":"no; nonce reuse repeats the stream and one-time authenticator key","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"96-bit nonce must be unique under a key","nonce_size":"96 bits","normative_status":"RFC 8439 (Informational CFRG consensus)","object_type":"AEAD","online":"yes for computation; plaintext release should follow tag verification","output_compatibility":null,"packing":null,"paper_title":"ChaCha20 and Poly1305 for IETF Protocols","paper_url":"https://www.rfc-editor.org/rfc/rfc8439.html","parallelizable":"ChaCha20 blocks yes; Poly1305 is incremental","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"authenticated_encryption","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"nonce-based AEAD","security_model":"stream cipher plus one-time MAC","security_notion":"authenticated encryption with associated data","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"256 bits","nonce":"96 bits","tag":"128 bits"},"statefulness":null,"summary":"The RFC is a stable algorithm reference; its Informational status is not silently relabeled as an Internet Standard.","supported_gates":null,"tag_size":"128 bits","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2018-RFC8439","year":2018},{"adaptive_security":null,"api_style":null,"associated_data":"yes","assumption_family":"symmetric","assumption_id":"SYM-ASSUMPTION-AES-AND-POLYVAL-BASED-SYNTHETIC-IV-SECURITY","assumption_name":"AES and POLYVAL-based synthetic-IV security","authors":["Shay Gueron","Adam Langley","Yehuda Lindell"],"base_signature":null,"block_size":"128-bit AES/POLYVAL blocks","bootstrapping":null,"capabilities":["nonce-misuse-resistance","associated-data","parallel-processing"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"synthetic_iv_plus_counter","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2019-GCMSIV","identifiable_abort":null,"key_size":"128 or 256 bits","large_universe":null,"misuse_resistance":"yes for accidental repetition within documented limits; equality leakage remains","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"96-bit nonce; uniqueness is recommended but accidental repetition has bounded degradation","nonce_size":"96 bits","normative_status":"RFC 8452 (Informational)","object_type":"misuse_resistant_AEAD","online":"no; tag/synthetic IV is computed before encryption","output_compatibility":null,"packing":null,"paper_title":"AES-GCM-SIV — Nonce Misuse-Resistant Authenticated Encryption","paper_url":"https://www.rfc-editor.org/rfc/rfc8452.html","parallelizable":"POLYVAL and CTR admit parallel implementation strategies","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"authenticated_encryption","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"synthetic-IV AEAD","security_model":"per-record keys plus POLYVAL and CTR","security_notion":"nonce-misuse-resistant authenticated encryption","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"128 / 256 bits","nonce":"96 bits","tag":"128 bits"},"statefulness":null,"summary":"GCM-SIV is a distinct construction from GCM; their nonce-failure behavior must not be merged.","supported_gates":null,"tag_size":"128 bits","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2019-GCMSIV","year":2019},{"adaptive_security":null,"api_style":null,"associated_data":"yes","assumption_family":"permutation-based symmetric","assumption_id":"SYM-ASSUMPTION-SECURITY-OF-THE-STANDARDIZED-ASCON-PERMUTATION-BASED-MODE","assumption_name":"security of the standardized Ascon permutation-based mode","authors":["Meltem Sönmez Turan","Kerry McKay","Jinkeon Kang","John Kelsey","Donghoon Chang"],"base_signature":null,"block_size":"128-bit rate over a 320-bit permutation state","bootstrapping":null,"capabilities":["lightweight-aead","associated-data","constrained-device-profile"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":null,"construction_family":"permutation_based_duplex","correctness":null,"corruption_model":null,"decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","identifiable_abort":null,"key_size":"128 bits","large_universe":null,"misuse_resistance":"no; the standardized AEAD is nonce respecting","multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":"128-bit nonce must be unique under a key","nonce_size":"128 bits","normative_status":"NIST SP 800-232","object_type":"lightweight_AEAD","online":"incremental processing; plaintext release should follow tag verification","output_compatibility":null,"packing":null,"paper_title":"Ascon-Based Lightweight Cryptography Standards for Constrained Devices","paper_url":"https://csrc.nist.gov/pubs/sp/800/232/final","parallelizable":"permutation dependency is sequential within a message","plaintext_space":null,"policy_class":null,"post_quantum_mechanism":null,"preprocessing":null,"primitive":"authenticated_encryption","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":null,"response_communication":null,"robustness":null,"security_mode":"nonce-based lightweight AEAD","security_model":"permutation-based duplex","security_notion":"authenticated encryption with associated data","server_model":null,"server_work":null,"setup_model":null,"signer_model":null,"signing_cost":null,"signing_rounds":null,"sizes":{"key":"128 bits","nonce":"128 bits","tag":"128 bits"},"statefulness":null,"summary":"This row uses the final 2025 NIST profile, not the byte-order and naming conventions of earlier Ascon submissions.","supported_gates":null,"tag_size":"128 bits","threshold_policy":null,"transform":null,"update_model":null,"verification_cost":null,"verification_status":"normative_source_reviewed","work_id":"SYM-PAPER-2025-SP800232","year":2025}],"edges":[{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-040630A1FB44BC","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2018-CHACHAPOLY","target":"SYM-PAPER-2018-RFC8439","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-072E67BEA18858","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2018-CHACHAPOLY","target":"SYM-ASSUMPTION-CHACHA20-STREAM-SECURITY-PLUS-POLY1305-ONE-TIME-AUTHENTICATION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-1CF9BEE9089F44","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-1977-DES","target":"SYM-ASSUMPTION-HISTORICAL-DES-BLOCK-CIPHER-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-23B7364629E2D1","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2007-GCM","target":"SYM-ASSUMPTION-AES-PRP-PLUS-UNIVERSAL-HASH-BOUNDS","type":"RELIES_ON"},{"evidenceLocator":"RFC 8439 Sections 2.3–2.8","evidenceUrl":"https://www.rfc-editor.org/rfc/rfc8439.html","id":"SYM-REL-242A80388AF320","note":"RFC 8439 fixes the ChaCha20 profile and composes it with a one-time Poly1305 authenticator to define an AEAD.","resultId":"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER","target":"SYM-RESULT-2018-RFC8439-CHACHA20-POLY1305-AEAD","type":"COMPOSES"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-2480F2418386F9","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2004-CCM","target":"SYM-RESULT-2004-CCM-CCM-CTR-CBC-MAC-AEAD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-294A8CBF1247E1","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2025-ASCONAEAD128","target":"SYM-PAPER-2025-SP800232","type":"DESCRIBED_IN"},{"evidenceLocator":"RFC 5297 Sections 2.2 and 2.6","evidenceUrl":"https://www.rfc-editor.org/rfc/rfc5297.html","id":"SYM-REL-2CFC16626A5312","note":"AES-SIV computes a synthetic IV with S2V and then uses the result as the counter-mode input for encryption.","resultId":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","target":"SYM-RESULT-2008-SIV-AES-SIV-NONCE-MISUSE-RESISTANT-AEAD","type":"COMBINES"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-44614117454093","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2004-CCM","target":"SYM-PAPER-2004-CCM","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-52A152C8884EB7","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2008-SIV","target":"SYM-RESULT-2008-SIV-AES-SIV-NONCE-MISUSE-RESISTANT-AEAD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-5F30911490B904","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2025-ASCONAEAD128","target":"SYM-ASSUMPTION-SECURITY-OF-THE-STANDARDIZED-ASCON-PERMUTATION-BASED-MODE","type":"RELIES_ON"},{"evidenceLocator":"RFC 8452 Sections 3–6","evidenceUrl":"https://www.rfc-editor.org/rfc/rfc8452.html","id":"SYM-REL-68AEC41F70B602","note":"AES-GCM-SIV changes GCM's nonce-failure profile by deriving per-record keys and a synthetic IV before counter-mode encryption.","resultId":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","target":"SYM-RESULT-2019-GCMSIV-AES-GCM-SIV-MISUSE-RESISTANT-AEAD","type":"HARDENS"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-69FFB2A2EA86A0","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-1977-DES","target":"SYM-PAPER-1977-DES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-6E4A2B73976A3C","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2001-AESCBC","target":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"SP 800-232 Abstract and Sections 3–4","evidenceUrl":"https://csrc.nist.gov/pubs/sp/800/232/final","id":"SYM-REL-8386C96CF59604","note":"SP 800-232 standardizes the selected Ascon family as Ascon-AEAD128 and related hash/XOF algorithms with a fixed NIST profile.","resultId":"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD","target":"SYM-RESULT-2025-SP800232-ASCON-AEAD128-NORMATIVE-STANDARD","type":"STANDARDIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-9077C9C7F510FC","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2007-GCM","target":"SYM-PAPER-2007-GCM","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-92EA57A9AD673C","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2008-CHACHA","target":"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-97C13BC532F3EE","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2008-CHACHA","target":"SYM-ASSUMPTION-CHACHA-ARX-STREAM-CIPHER-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"SP 800-38A Sections 1, 5, and 6.2","evidenceUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","id":"SYM-REL-9A95A90FFCFAD4","note":"SP 800-38A specifies CBC as a confidentiality mode over an approved block cipher such as AES; it does not add authentication.","resultId":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","target":"SYM-RESULT-2001-SP80038A-CBC-CONFIDENTIALITY-MODE","type":"USES_PRIMITIVE"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-9E8C38EC810161","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2008-AESSIV","target":"SYM-ASSUMPTION-AES-CMAC-PRF-AND-AES-CTR-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-A0529CE8EB1080","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2025-SP800232","target":"SYM-RESULT-2025-SP800232-ASCON-AEAD128-NORMATIVE-STANDARD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-A9311DB1A5AECC","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2007-GCM","target":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-AB24B189EF9D69","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2014-ASCON","target":"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD","type":"HAS_RESULT"},{"evidenceLocator":"SP 800-38C Sections 1 and 6","evidenceUrl":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","id":"SYM-REL-B01D7A573FF47A","note":"CCM combines CTR-mode encryption with CBC-MAC authentication and a formatted associated-data input.","resultId":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","target":"SYM-RESULT-2004-CCM-CCM-CTR-CBC-MAC-AEAD","type":"COMBINES"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-B15DAD5F03453A","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2018-RFC8439","target":"SYM-RESULT-2018-RFC8439-CHACHA20-POLY1305-AEAD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-C3181A4D10B5C9","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2001-AES","target":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-C8C68F56DE9D2C","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2001-AES","target":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-C90DD1EB84E9D3","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2001-SP80038A","target":"SYM-RESULT-2001-SP80038A-CBC-CONFIDENTIALITY-MODE","type":"HAS_RESULT"},{"evidenceLocator":"SP 800-38A Sections 1, 5, and 6.5","evidenceUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","id":"SYM-REL-C941D9A556040A","note":"SP 800-38A specifies CTR as a confidentiality mode over an approved block cipher such as AES; counter blocks must remain distinct under one key.","resultId":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","target":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","type":"USES_PRIMITIVE"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-CB52BA6201248B","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2004-CCM","target":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-CBFF7AF464045B","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2019-GCMSIV","target":"SYM-RESULT-2019-GCMSIV-AES-GCM-SIV-MISUSE-RESISTANT-AEAD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-D29466F9553EC4","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2001-AESCTR","target":"SYM-PAPER-2001-SP80038A","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-D2BD7442E0A1B0","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-2001-SP80038A","target":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","type":"HAS_RESULT"},{"evidenceLocator":"SP 800-38D Sections 5–7","evidenceUrl":"https://csrc.nist.gov/pubs/sp/800/38/d/final","id":"SYM-REL-D36F849F24999F","note":"GCM uses counter-mode encryption and adds GHASH polynomial authentication to obtain AEAD.","resultId":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","reviewStatus":"primary_source_checked","source":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","target":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","type":"COMBINES"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-DBCB5CB75B98DD","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2019-GCMSIV","target":"SYM-PAPER-2019-GCMSIV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-E3A623D41B8845","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2001-AES","target":"SYM-PAPER-2001-AES","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-E6776CDCBF1124","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2008-CHACHA","target":"SYM-PAPER-2008-CHACHA","type":"DESCRIBED_IN"},{"evidenceLocator":"FIPS 197 Introduction and NIST AES selection history","evidenceUrl":"https://csrc.nist.gov/pubs/fips/197/final","id":"SYM-REL-EAD8D155974114","note":"FIPS 197 standardizes AES after the AES competition as the replacement for the aging DES standard, with a 128-bit block and larger keys.","resultId":"SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD","reviewStatus":"primary_source_checked","source":"SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD","target":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","type":"SUPERSEDES_STANDARD"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-EC415EAA677404","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-PAPER-1977-DES","target":"SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-EF753260278C33","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2019-GCMSIV","target":"SYM-ASSUMPTION-AES-AND-POLYVAL-BASED-SYNTHETIC-IV-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-EF7AB20A86CD2D","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"SYM-CONSTRUCTION-2001-AESCTR","target":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-FA3245A44B5FBF","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2008-AESSIV","target":"SYM-PAPER-2008-SIV","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"SYM-REL-FE4E9D22A31D28","note":"","resultId":null,"reviewStatus":"source_declared","source":"SYM-CONSTRUCTION-2001-AESCBC","target":"SYM-PAPER-2001-SP80038A","type":"DESCRIBED_IN"}],"nodes":[{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-AES-AND-POLYVAL-BASED-SYNTHETIC-IV-SECURITY","keywords":["symmetric"],"metadata":{"family":"symmetric","name":"AES and POLYVAL-based synthetic-IV security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric","summary":"Assumption used by one or more Symmetric/AEAD construction records: AES and POLYVAL-based synthetic-IV security.","title":"AES and POLYVAL-based synthetic-IV security","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-AES-AND-POLYVAL-BASED-SYNTHETIC-IV-SECURITY"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-AES-CMAC-PRF-AND-AES-CTR-SECURITY","keywords":["symmetric"],"metadata":{"family":"symmetric","name":"AES-CMAC PRF and AES-CTR security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric","summary":"Assumption used by one or more Symmetric/AEAD construction records: AES-CMAC PRF and AES-CTR security.","title":"AES-CMAC PRF and AES-CTR security","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-AES-CMAC-PRF-AND-AES-CTR-SECURITY"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-AES-PRP-PLUS-UNIVERSAL-HASH-BOUNDS","keywords":["symmetric"],"metadata":{"family":"symmetric","name":"AES PRP plus universal-hash bounds"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric","summary":"Assumption used by one or more Symmetric/AEAD construction records: AES PRP plus universal-hash bounds.","title":"AES PRP plus universal-hash bounds","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-AES-PRP-PLUS-UNIVERSAL-HASH-BOUNDS"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY","keywords":["symmetric cryptanalysis"],"metadata":{"family":"symmetric cryptanalysis","name":"AES pseudorandom-permutation security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric cryptanalysis","summary":"Assumption used by one or more Symmetric/AEAD construction records: AES pseudorandom-permutation security.","title":"AES pseudorandom-permutation security","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-AES-PSEUDORANDOM-PERMUTATION-SECURITY"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-CHACHA-ARX-STREAM-CIPHER-SECURITY","keywords":["symmetric cryptanalysis"],"metadata":{"family":"symmetric cryptanalysis","name":"ChaCha ARX stream-cipher security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric cryptanalysis","summary":"Assumption used by one or more Symmetric/AEAD construction records: ChaCha ARX stream-cipher security.","title":"ChaCha ARX stream-cipher security","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-CHACHA-ARX-STREAM-CIPHER-SECURITY"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-CHACHA20-STREAM-SECURITY-PLUS-POLY1305-ONE-TIME-AUTHENTICATION","keywords":["symmetric composition"],"metadata":{"family":"symmetric composition","name":"ChaCha20 stream security plus Poly1305 one-time authentication"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric composition","summary":"Assumption used by one or more Symmetric/AEAD construction records: ChaCha20 stream security plus Poly1305 one-time authentication.","title":"ChaCha20 stream security plus Poly1305 one-time authentication","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-CHACHA20-STREAM-SECURITY-PLUS-POLY1305-ONE-TIME-AUTHENTICATION"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-HISTORICAL-DES-BLOCK-CIPHER-SECURITY","keywords":["symmetric cryptanalysis"],"metadata":{"family":"symmetric cryptanalysis","name":"historical DES block-cipher security"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"symmetric cryptanalysis","summary":"Assumption used by one or more Symmetric/AEAD construction records: historical DES block-cipher security.","title":"historical DES block-cipher security","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-HISTORICAL-DES-BLOCK-CIPHER-SECURITY"},{"evidence":"scheme_declared","id":"SYM-ASSUMPTION-SECURITY-OF-THE-STANDARDIZED-ASCON-PERMUTATION-BASED-MODE","keywords":["permutation-based symmetric"],"metadata":{"family":"permutation-based symmetric","name":"security of the standardized Ascon permutation-based mode"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"permutation-based symmetric","summary":"Assumption used by one or more Symmetric/AEAD construction records: security of the standardized Ascon permutation-based mode.","title":"security of the standardized Ascon permutation-based mode","type":"assumption","venue":null,"year":null,"sourcePath":"data/symmetric-aead-catalog.json#SYM-ASSUMPTION-SECURITY-OF-THE-STANDARDIZED-ASCON-PERMUTATION-BASED-MODE"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-1977-DES","keywords":["symmetric_block_cipher","feistel","block-permutation"],"metadata":{"associated_data":"no","assumption":{"family":"symmetric cryptanalysis","name":"historical DES block-cipher security"},"block_size":"64 bits","capabilities":["block-permutation"],"construction_family":"feistel","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-1977-DES","key_size":"56-bit effective key","misuse_resistance":"not applicable; mode-defined","name":"DES","nonce_requirement":"not applicable to the primitive","nonce_size":"not applicable","normative_status":"withdrawn and superseded; historical only","object_type":"block_cipher","online":"one block at a time","parallelizable":"independent block calls","primitive":"symmetric_block_cipher","security":{"mode":"primitive","model":"concrete cryptanalysis","notion":"block-cipher pseudorandomness target"},"sizes":{"block":"64 bits","key":"56 effective bits"},"status":"withdrawn","tag_size":"not applicable","title":"DES","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-1977-DES","year":1977},"primaryUrl":"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub46.pdf","sections":[{"content":"DES is included only to explain the standardization transition to AES.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"symmetric_block_cipher · 1977","summary":"DES is included only to explain the standardization transition to AES.","title":"DES","type":"construction","venue":"FIPS PUB 46","year":1977,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-1977-DES"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2001-AES","keywords":["symmetric_block_cipher","substitution_permutation_network","block-permutation","standardized-primitive"],"metadata":{"associated_data":"no","assumption":{"family":"symmetric cryptanalysis","name":"AES pseudorandom-permutation security"},"block_size":"128 bits","capabilities":["block-permutation","standardized-primitive"],"construction_family":"substitution_permutation_network","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2001-AES","key_size":"128 / 192 / 256 bits","misuse_resistance":"not applicable; mode-defined","name":"AES","nonce_requirement":"not applicable to the primitive","nonce_size":"not applicable","normative_status":"FIPS 197","object_type":"block_cipher","online":"one block at a time","parallelizable":"independent block calls","primitive":"symmetric_block_cipher","security":{"mode":"primitive","model":"concrete cryptanalysis","notion":"block-cipher PRP target"},"sizes":{"block":"128 bits","key":"128 / 192 / 256 bits"},"status":"standard","tag_size":"not applicable","title":"AES","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2001-AES","year":2001},"primaryUrl":"https://csrc.nist.gov/pubs/fips/197/final","sections":[{"content":"AES is a primitive. Confidentiality and authentication properties depend on the mode that uses it.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"symmetric_block_cipher · 2001","summary":"AES is a primitive. Confidentiality and authentication properties depend on the mode that uses it.","title":"AES","type":"construction","venue":"FIPS 197","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2001-AES"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2001-AESCBC","keywords":["symmetric_encryption_mode","cipher_block_chaining","variable-length-confidentiality"],"metadata":{"associated_data":"no","assumption":{"family":"symmetric","name":"AES pseudorandom-permutation security"},"block_size":"128-bit data blocks; padding, when needed, is outside the mode specification","capabilities":["variable-length-confidentiality"],"construction_family":"cipher_block_chaining","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2001-AESCBC","key_size":"AES key size","misuse_resistance":"no; IV failure can reveal relations and the mode provides no integrity","name":"AES-CBC","nonce_requirement":"unpredictable 128-bit IV for encryption","nonce_size":"128-bit IV","normative_status":"NIST SP 800-38A; confidentiality only","object_type":"confidentiality_mode","online":"encryption is sequential","parallelizable":"encryption no; decryption block calls yes","primitive":"symmetric_encryption_mode","security":{"mode":"secret-key encryption","model":"block-cipher mode","notion":"confidentiality with proper randomized IV handling"},"sizes":{"iv":"128 bits","key":"AES key","tag":"none"},"status":"standard","tag_size":"none","title":"AES-CBC","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2001-SP80038A","year":2001},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","sections":[{"content":"CBC does not authenticate ciphertext. Padding and composition rules are outside this row.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"symmetric_encryption_mode · 2001","summary":"CBC does not authenticate ciphertext. Padding and composition rules are outside this row.","title":"AES-CBC","type":"construction","venue":"NIST SP 800-38A","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2001-AESCBC"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2001-AESCTR","keywords":["symmetric_encryption_mode","counter_mode","random-access-confidentiality","parallel-block-processing"],"metadata":{"associated_data":"no","assumption":{"family":"symmetric","name":"AES pseudorandom-permutation security"},"block_size":"byte/bit stream derived from 128-bit blocks","capabilities":["random-access-confidentiality","parallel-block-processing"],"construction_family":"counter_mode","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2001-AESCTR","key_size":"AES key size","misuse_resistance":"no; keystream reuse exposes plaintext relations","name":"AES-CTR","nonce_requirement":"counter blocks must be unique under a key","nonce_size":"profile-defined counter block totaling 128 bits","normative_status":"NIST SP 800-38A; confidentiality only","object_type":"confidentiality_mode","online":"yes","parallelizable":"yes","primitive":"symmetric_encryption_mode","security":{"mode":"secret-key encryption","model":"block-cipher mode","notion":"confidentiality under unique counters"},"sizes":{"counter_block":"128 bits","key":"AES key","tag":"none"},"status":"standard","tag_size":"none","title":"AES-CTR","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2001-SP80038A","year":2001},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","sections":[{"content":"CTR is a confidentiality component used inside several AEAD constructions; it provides no integrity by itself.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"symmetric_encryption_mode · 2001","summary":"CTR is a confidentiality component used inside several AEAD constructions; it provides no integrity by itself.","title":"AES-CTR","type":"construction","venue":"NIST SP 800-38A","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2001-AESCTR"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2004-CCM","keywords":["authenticated_encryption","ctr_plus_cbc_mac","confidentiality","integrity","associated-data"],"metadata":{"associated_data":"yes","assumption":{"family":"symmetric","name":"AES pseudorandom-permutation security"},"block_size":"128-bit AES blocks","capabilities":["confidentiality","integrity","associated-data"],"construction_family":"ctr_plus_cbc_mac","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2004-CCM","key_size":"AES key size","misuse_resistance":"no; nonce repetition violates the security contract","name":"AES-CCM","nonce_requirement":"nonce must be unique under a key","nonce_size":"56–104 bits (7–13 octets)","normative_status":"NIST SP 800-38C","object_type":"AEAD","online":"no; CBC-MAC and message length precede CTR encryption","parallelizable":"CTR portion yes; CBC-MAC portion no","primitive":"authenticated_encryption","security":{"mode":"nonce-based AEAD","model":"composed block-cipher modes","notion":"authenticated encryption with associated data"},"sizes":{"key":"AES key","nonce":"7–13 octets","tag":"4–16 octets subject to profile"},"status":"standard","tag_size":"32–128 bits in permitted even-byte increments","title":"AES-CCM","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2004-CCM","year":2004},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","sections":[{"content":"CCM combines two sequential views of the message and is not a one-pass online AEAD.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"authenticated_encryption · 2004","summary":"CCM combines two sequential views of the message and is not a one-pass online AEAD.","title":"AES-CCM","type":"construction","venue":"NIST SP 800-38C","year":2004,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2004-CCM"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2007-GCM","keywords":["authenticated_encryption","counter_plus_galois_hash","confidentiality","integrity","associated-data","parallel-processing"],"metadata":{"associated_data":"yes","assumption":{"family":"symmetric","name":"AES PRP plus universal-hash bounds"},"block_size":"128-bit AES and GHASH blocks","capabilities":["confidentiality","integrity","associated-data","parallel-processing"],"construction_family":"counter_plus_galois_hash","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2007-GCM","key_size":"AES key size","misuse_resistance":"no; repeated IVs can catastrophically damage confidentiality and authentication","name":"AES-GCM","nonce_requirement":"IV uniqueness is critical; 96 bits is the recommended interoperable length","nonce_size":"96 bits recommended; other lengths are processed by GHASH","normative_status":"NIST SP 800-38D","object_type":"AEAD","online":"yes","parallelizable":"yes for CTR and GHASH evaluation strategies","primitive":"authenticated_encryption","security":{"mode":"nonce-based AEAD","model":"counter mode plus polynomial authentication","notion":"authenticated encryption with associated data"},"sizes":{"key":"AES key","nonce":"96 bits recommended","tag":"up to 128 bits"},"status":"standard","tag_size":"profile-selected up to 128 bits with NIST constraints","title":"AES-GCM","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2007-GCM","year":2007},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/d/final","sections":[{"content":"The row makes nonce uniqueness prominent because GCM’s failure mode under reuse is a defining deployment constraint.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"authenticated_encryption · 2007","summary":"The row makes nonce uniqueness prominent because GCM’s failure mode under reuse is a defining deployment constraint.","title":"AES-GCM","type":"construction","venue":"NIST SP 800-38D","year":2007,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2007-GCM"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2008-AESSIV","keywords":["authenticated_encryption","synthetic_iv","nonce-misuse-resistance","deterministic-aead","associated-data-vector"],"metadata":{"associated_data":"yes; vector of associated-data strings","assumption":{"family":"symmetric","name":"AES-CMAC PRF and AES-CTR security"},"block_size":"128-bit AES blocks","capabilities":["nonce-misuse-resistance","deterministic-aead","associated-data-vector"],"construction_family":"synthetic_iv","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2008-AESSIV","key_size":"256 / 384 / 512 bits split across S2V and CTR","misuse_resistance":"yes; repeated inputs reveal equality but do not cause GCM-style key recovery","name":"AES-SIV","nonce_requirement":"optional; uniqueness improves privacy but repetition is tolerated with bounded leakage","nonce_size":"optional associated-data component; 128-bit random nonce recommended when used","normative_status":"RFC 5297 (Informational)","object_type":"misuse_resistant_AEAD","online":"no; synthetic IV is computed before CTR encryption","parallelizable":"CTR phase yes; S2V/CMAC chain limited","primitive":"authenticated_encryption","security":{"mode":"synthetic-IV AEAD","model":"S2V plus CTR","notion":"deterministic/misuse-resistant authenticated encryption"},"sizes":{"key":"256 / 384 / 512 bits","nonce":"optional","tag":"128 bits"},"status":"rfc","tag_size":"128-bit synthetic IV","title":"AES-SIV","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2008-SIV","year":2008},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc5297.html","sections":[{"content":"“Misuse resistant” is not “misuse proof”: deterministic equality leakage and usage limits remain.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"authenticated_encryption · 2008","summary":"“Misuse resistant” is not “misuse proof”: deterministic equality leakage and usage limits remain.","title":"AES-SIV","type":"construction","venue":"RFC 5297","year":2008,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2008-AESSIV"},{"evidence":"primary_source_reviewed","id":"SYM-CONSTRUCTION-2008-CHACHA","keywords":["symmetric_stream_cipher","arx","software-oriented-stream-encryption","random-access-keystream"],"metadata":{"associated_data":"no","assumption":{"family":"symmetric cryptanalysis","name":"ChaCha ARX stream-cipher security"},"block_size":"512-bit keystream blocks","capabilities":["software-oriented-stream-encryption","random-access-keystream"],"construction_family":"arx","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2008-CHACHA","key_size":"256 bits in the primary profile","misuse_resistance":"no; repeated keystream exposes plaintext relations","name":"ChaCha stream cipher family","nonce_requirement":"nonce/counter input must not repeat under a key","nonce_size":"64 bits in the original family presentation","normative_status":"research construction; RFC 8439 defines the IETF ChaCha20 profile","object_type":"stream_cipher","online":"yes","parallelizable":"block-function calls can be parallelized","primitive":"symmetric_stream_cipher","security":{"mode":"stream cipher","model":"concrete cryptanalysis","notion":"pseudorandom keystream target"},"sizes":{"key":"256 bits","keystream_block":"512 bits","nonce":"64 bits in original profile"},"status":"published","tag_size":"none","title":"ChaCha stream cipher family","verification":{"status":"primary_source_reviewed"},"work_id":"SYM-PAPER-2008-CHACHA","year":2008},"primaryUrl":"https://cr.yp.to/chacha/chacha-20080128.pdf","sections":[{"content":"The original family and the later 96-bit-nonce IETF profile are kept as distinct rows.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"symmetric_stream_cipher · 2008","summary":"The original family and the later 96-bit-nonce IETF profile are kept as distinct rows.","title":"ChaCha stream cipher family","type":"construction","venue":"SASC 2008","year":2008,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2008-CHACHA"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","keywords":["authenticated_encryption","stream_cipher_plus_one_time_mac","confidentiality","integrity","associated-data","software-portability"],"metadata":{"associated_data":"yes","assumption":{"family":"symmetric composition","name":"ChaCha20 stream security plus Poly1305 one-time authentication"},"block_size":"512-bit ChaCha20 blocks; 16-byte Poly1305 processing","capabilities":["confidentiality","integrity","associated-data","software-portability"],"construction_family":"stream_cipher_plus_one_time_mac","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","key_size":"256 bits","misuse_resistance":"no; nonce reuse repeats the stream and one-time authenticator key","name":"ChaCha20-Poly1305","nonce_requirement":"96-bit nonce must be unique under a key","nonce_size":"96 bits","normative_status":"RFC 8439 (Informational CFRG consensus)","object_type":"AEAD","online":"yes for computation; plaintext release should follow tag verification","parallelizable":"ChaCha20 blocks yes; Poly1305 is incremental","primitive":"authenticated_encryption","security":{"mode":"nonce-based AEAD","model":"stream cipher plus one-time MAC","notion":"authenticated encryption with associated data"},"sizes":{"key":"256 bits","nonce":"96 bits","tag":"128 bits"},"status":"rfc","tag_size":"128 bits","title":"ChaCha20-Poly1305","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2018-RFC8439","year":2018},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc8439.html","sections":[{"content":"The RFC is a stable algorithm reference; its Informational status is not silently relabeled as an Internet Standard.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"authenticated_encryption · 2018","summary":"The RFC is a stable algorithm reference; its Informational status is not silently relabeled as an Internet Standard.","title":"ChaCha20-Poly1305","type":"construction","venue":"RFC 8439","year":2018,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2018-CHACHAPOLY"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2019-GCMSIV","keywords":["authenticated_encryption","synthetic_iv_plus_counter","nonce-misuse-resistance","associated-data","parallel-processing"],"metadata":{"associated_data":"yes","assumption":{"family":"symmetric","name":"AES and POLYVAL-based synthetic-IV security"},"block_size":"128-bit AES/POLYVAL blocks","capabilities":["nonce-misuse-resistance","associated-data","parallel-processing"],"construction_family":"synthetic_iv_plus_counter","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2019-GCMSIV","key_size":"128 or 256 bits","misuse_resistance":"yes for accidental repetition within documented limits; equality leakage remains","name":"AES-GCM-SIV","nonce_requirement":"96-bit nonce; uniqueness is recommended but accidental repetition has bounded degradation","nonce_size":"96 bits","normative_status":"RFC 8452 (Informational)","object_type":"misuse_resistant_AEAD","online":"no; tag/synthetic IV is computed before encryption","parallelizable":"POLYVAL and CTR admit parallel implementation strategies","primitive":"authenticated_encryption","security":{"mode":"synthetic-IV AEAD","model":"per-record keys plus POLYVAL and CTR","notion":"nonce-misuse-resistant authenticated encryption"},"sizes":{"key":"128 / 256 bits","nonce":"96 bits","tag":"128 bits"},"status":"rfc","tag_size":"128 bits","title":"AES-GCM-SIV","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2019-GCMSIV","year":2019},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc8452.html","sections":[{"content":"GCM-SIV is a distinct construction from GCM; their nonce-failure behavior must not be merged.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"authenticated_encryption · 2019","summary":"GCM-SIV is a distinct construction from GCM; their nonce-failure behavior must not be merged.","title":"AES-GCM-SIV","type":"construction","venue":"RFC 8452","year":2019,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2019-GCMSIV"},{"evidence":"normative_source_reviewed","id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","keywords":["authenticated_encryption","permutation_based_duplex","lightweight-aead","associated-data","constrained-device-profile"],"metadata":{"associated_data":"yes","assumption":{"family":"permutation-based symmetric","name":"security of the standardized Ascon permutation-based mode"},"block_size":"128-bit rate over a 320-bit permutation state","capabilities":["lightweight-aead","associated-data","constrained-device-profile"],"construction_family":"permutation_based_duplex","dossier_type":"construction","evidence":"primary_source_checked","id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","key_size":"128 bits","misuse_resistance":"no; the standardized AEAD is nonce respecting","name":"Ascon-AEAD128","nonce_requirement":"128-bit nonce must be unique under a key","nonce_size":"128 bits","normative_status":"NIST SP 800-232","object_type":"lightweight_AEAD","online":"incremental processing; plaintext release should follow tag verification","parallelizable":"permutation dependency is sequential within a message","primitive":"authenticated_encryption","security":{"mode":"nonce-based lightweight AEAD","model":"permutation-based duplex","notion":"authenticated encryption with associated data"},"sizes":{"key":"128 bits","nonce":"128 bits","tag":"128 bits"},"status":"standard","tag_size":"128 bits","title":"Ascon-AEAD128","verification":{"status":"normative_source_reviewed"},"work_id":"SYM-PAPER-2025-SP800232","year":2025},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/232/final","sections":[{"content":"This row uses the final 2025 NIST profile, not the byte-order and naming conventions of earlier Ascon submissions.","heading":"Construction note"}],"status":"normative_source_reviewed","subtitle":"authenticated_encryption · 2025","summary":"This row uses the final 2025 NIST profile, not the byte-order and naming conventions of earlier Ascon submissions.","title":"Ascon-AEAD128","type":"construction","venue":"NIST SP 800-232","year":2025,"sourcePath":"data/symmetric-aead-catalog.json#SYM-CONSTRUCTION-2025-ASCONAEAD128"},{"evidence":"primary_source_checked","id":"SYM-PAPER-1977-DES","keywords":["des","block-cipher","standard","historical"],"metadata":{"authors":["National Bureau of Standards"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-1977-DES","keywords":["des","block-cipher","standard","historical"],"primary_url":"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub46.pdf","status":"withdrawn","title":"Data Encryption Standard","venue":"FIPS PUB 46","year":1977},"primaryUrl":"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub46.pdf","sections":[{"content":"Standardizes DES as a 64-bit block cipher with a 56-bit effective key. Its current role in the atlas is historical.","heading":"Atomic claims"},{"content":"FIPS PUB 46, specification and algorithm description.","heading":"Evidence locator"}],"status":"withdrawn","subtitle":"National Bureau of Standards · 1977","summary":"Standardizes DES as a 64-bit block cipher with a 56-bit effective key. Its current role in the atlas is historical.","title":"Data Encryption Standard","type":"paper","venue":"FIPS PUB 46","year":1977,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-1977-DES"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2001-AES","keywords":["aes","rijndael","block-cipher","nist","standard"],"metadata":{"authors":["National Institute of Standards and Technology"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2001-AES","keywords":["aes","rijndael","block-cipher","nist","standard"],"primary_url":"https://csrc.nist.gov/pubs/fips/197/final","status":"published","title":"Advanced Encryption Standard (AES)","venue":"FIPS 197","year":2001},"primaryUrl":"https://csrc.nist.gov/pubs/fips/197/final","sections":[{"content":"Standardizes AES-128, AES-192, and AES-256, each operating on 128-bit blocks.","heading":"Atomic claims"},{"content":"FIPS 197 abstract and Sections 3–5.","heading":"Evidence locator"}],"status":"published","subtitle":"National Institute of Standards and Technology · 2001","summary":"Standardizes AES-128, AES-192, and AES-256, each operating on 128-bit blocks.","title":"Advanced Encryption Standard (AES)","type":"paper","venue":"FIPS 197","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2001-AES"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2001-SP80038A","keywords":["aes","cbc","ctr","mode","nist"],"metadata":{"authors":["Morris Dworkin"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2001-SP80038A","keywords":["aes","cbc","ctr","mode","nist"],"primary_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","status":"published","title":"Recommendation for Block Cipher Modes of Operation — Methods and Techniques","venue":"NIST SP 800-38A","year":2001},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","sections":[{"content":"Specifies five confidentiality modes for an approved block cipher, including CBC and CTR. These modes do not by themselves authenticate ciphertexts.","heading":"Atomic claims"},{"content":"SP 800-38A Sections 5, 6.2, and 6.5.","heading":"Evidence locator"}],"status":"published","subtitle":"Morris Dworkin · 2001","summary":"Specifies five confidentiality modes for an approved block cipher, including CBC and CTR. These modes do not by themselves authenticate ciphertexts.","title":"Recommendation for Block Cipher Modes of Operation — Methods and Techniques","type":"paper","venue":"NIST SP 800-38A","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2001-SP80038A"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2004-CCM","keywords":["ccm","aead","ctr","cbc-mac","nist"],"metadata":{"authors":["Morris Dworkin"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2004-CCM","keywords":["ccm","aead","ctr","cbc-mac","nist"],"primary_url":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","status":"published","title":"Recommendation for Block Cipher Modes of Operation — The CCM Mode for Authentication and Confidentiality","venue":"NIST SP 800-38C","year":2004},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","sections":[{"content":"Specifies CCM authenticated encryption by combining counter-mode encryption with CBC-MAC authentication under a block cipher.","heading":"Atomic claims"},{"content":"SP 800-38C Sections 1, 5, and 6.","heading":"Evidence locator"}],"status":"published","subtitle":"Morris Dworkin · 2004","summary":"Specifies CCM authenticated encryption by combining counter-mode encryption with CBC-MAC authentication under a block cipher.","title":"Recommendation for Block Cipher Modes of Operation — The CCM Mode for Authentication and Confidentiality","type":"paper","venue":"NIST SP 800-38C","year":2004,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2004-CCM"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2007-GCM","keywords":["gcm","aead","ctr","universal-hash","nist"],"metadata":{"authors":["Morris Dworkin"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2007-GCM","keywords":["gcm","aead","ctr","universal-hash","nist"],"primary_url":"https://csrc.nist.gov/pubs/sp/800/38/d/final","status":"published","title":"Recommendation for Block Cipher Modes of Operation — Galois/Counter Mode (GCM) and GMAC","venue":"NIST SP 800-38D","year":2007},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/d/final","sections":[{"content":"Specifies GCM authenticated encryption and GMAC using counter-mode encryption and polynomial hashing over a binary field.","heading":"Atomic claims"},{"content":"SP 800-38D abstract and Sections 5–7.","heading":"Evidence locator"}],"status":"published","subtitle":"Morris Dworkin · 2007","summary":"Specifies GCM authenticated encryption and GMAC using counter-mode encryption and polynomial hashing over a binary field.","title":"Recommendation for Block Cipher Modes of Operation — Galois/Counter Mode (GCM) and GMAC","type":"paper","venue":"NIST SP 800-38D","year":2007,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2007-GCM"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2008-CHACHA","keywords":["chacha","stream-cipher","arx"],"metadata":{"authors":["Daniel J. Bernstein"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2008-CHACHA","keywords":["chacha","stream-cipher","arx"],"primary_url":"https://cr.yp.to/chacha/chacha-20080128.pdf","status":"published","title":"ChaCha, a Variant of Salsa20","venue":"SASC 2008","year":2008},"primaryUrl":"https://cr.yp.to/chacha/chacha-20080128.pdf","sections":[{"content":"Defines the ChaCha family of ARX stream ciphers as a variant of Salsa20 with a changed round function and diffusion pattern.","heading":"Atomic claims"},{"content":"Author-hosted paper, design and round-function sections.","heading":"Evidence locator"}],"status":"published","subtitle":"Daniel J. Bernstein · 2008","summary":"Defines the ChaCha family of ARX stream ciphers as a variant of Salsa20 with a changed round function and diffusion pattern.","title":"ChaCha, a Variant of Salsa20","type":"paper","venue":"SASC 2008","year":2008,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2008-CHACHA"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2008-SIV","keywords":["siv","misuse-resistant","aead","aes","rfc"],"metadata":{"authors":["Dan Harkins"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2008-SIV","keywords":["siv","misuse-resistant","aead","aes","rfc"],"primary_url":"https://www.rfc-editor.org/rfc/rfc5297.html","status":"published","title":"Synthetic Initialization Vector (SIV) Authenticated Encryption Using AES","venue":"RFC 5297","year":2008},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc5297.html","sections":[{"content":"Specifies AES-SIV using S2V to derive a synthetic IV and CTR mode for encryption, providing deterministic authenticated encryption and bounded resistance to nonce reuse.","heading":"Atomic claims"},{"content":"RFC 5297 Sections 1.3.2, 2.2, and 2.6.","heading":"Evidence locator"}],"status":"published","subtitle":"Dan Harkins · 2008","summary":"Specifies AES-SIV using S2V to derive a synthetic IV and CTR mode for encryption, providing deterministic authenticated encryption and bounded resistance to nonce reuse.","title":"Synthetic Initialization Vector (SIV) Authenticated Encryption Using AES","type":"paper","venue":"RFC 5297","year":2008,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2008-SIV"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2014-ASCON","keywords":["ascon","permutation","lightweight","aead"],"metadata":{"authors":["Christoph Dobraunig","Maria Eichlseder","Florian Mendel","Martin Schläffer"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2014-ASCON","keywords":["ascon","permutation","lightweight","aead"],"primary_url":"https://ascon.iaik.tugraz.at/files/ascon.pdf","status":"published","title":"Ascon v1 — Submission to the CAESAR Competition","venue":"CAESAR round-one submission","versions":[{"date":"2014-03-15","label":"Ascon v1 initial CAESAR submission used for the origin claim","url":"https://ascon.iaik.tugraz.at/files/ascon.pdf"},{"date":"2016-09-15","label":"Ascon v1.2 CAESAR revision","url":"https://ascon.isec.tugraz.at/files/asconv12.pdf"},{"date":"2021-05-31","label":"Ascon v1.2 NIST lightweight-cryptography submission; later and not byte-identical to the 2014 origin","url":"https://ascon.isec.tugraz.at/files/asconv12-nist.pdf"}],"year":2014},"primaryUrl":"https://ascon.iaik.tugraz.at/files/ascon.pdf","sections":[{"content":"Defines the Ascon family around a small permutation, including nonce-based authenticated encryption designed for lightweight environments.","heading":"Atomic claims"},{"content":"Ascon v1 initial CAESAR submission dated 2014-03-15, Sections 1.1–1.4. Later v1.2 and NIST profiles remain separately versioned.","heading":"Evidence locator"}],"status":"published","subtitle":"Christoph Dobraunig, Maria Eichlseder, Florian Mendel et al. · 2014","summary":"Defines the Ascon family around a small permutation, including nonce-based authenticated encryption designed for lightweight environments.","title":"Ascon v1 — Submission to the CAESAR Competition","type":"paper","venue":"CAESAR round-one submission","year":2014,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2014-ASCON"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2018-RFC8439","keywords":["chacha20","poly1305","aead","rfc","stream-cipher"],"metadata":{"authors":["Yoav Nir","Adam Langley"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2018-RFC8439","keywords":["chacha20","poly1305","aead","rfc","stream-cipher"],"primary_url":"https://www.rfc-editor.org/rfc/rfc8439.html","status":"published","title":"ChaCha20 and Poly1305 for IETF Protocols","venue":"RFC 8439","year":2018},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc8439.html","sections":[{"content":"Specifies ChaCha20, Poly1305, and their combined AEAD construction with a 256-bit key, 96-bit nonce, and 128-bit tag.","heading":"Atomic claims"},{"content":"RFC 8439 abstract and Sections 2.3–2.8.","heading":"Evidence locator"}],"status":"published","subtitle":"Yoav Nir, Adam Langley · 2018","summary":"Specifies ChaCha20, Poly1305, and their combined AEAD construction with a 256-bit key, 96-bit nonce, and 128-bit tag.","title":"ChaCha20 and Poly1305 for IETF Protocols","type":"paper","venue":"RFC 8439","year":2018,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2018-RFC8439"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2019-GCMSIV","keywords":["gcm-siv","siv","misuse-resistant","aead","rfc"],"metadata":{"authors":["Shay Gueron","Adam Langley","Yehuda Lindell"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2019-GCMSIV","keywords":["gcm-siv","siv","misuse-resistant","aead","rfc"],"primary_url":"https://www.rfc-editor.org/rfc/rfc8452.html","status":"published","title":"AES-GCM-SIV — Nonce Misuse-Resistant Authenticated Encryption","venue":"RFC 8452","year":2019},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc8452.html","sections":[{"content":"Specifies AES-GCM-SIV, deriving a synthetic IV and per-record keys to limit the consequences of accidental nonce repetition.","heading":"Atomic claims"},{"content":"RFC 8452 Abstract, Sections 3–6, and Section 9 security considerations and usage bounds.","heading":"Evidence locator"}],"status":"published","subtitle":"Shay Gueron, Adam Langley, Yehuda Lindell · 2019","summary":"Specifies AES-GCM-SIV, deriving a synthetic IV and per-record keys to limit the consequences of accidental nonce repetition.","title":"AES-GCM-SIV — Nonce Misuse-Resistant Authenticated Encryption","type":"paper","venue":"RFC 8452","year":2019,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2019-GCMSIV"},{"evidence":"primary_source_checked","id":"SYM-PAPER-2025-SP800232","keywords":["ascon","permutation","lightweight","aead","nist","standard"],"metadata":{"authors":["Meltem Sönmez Turan","Kerry McKay","Jinkeon Kang","John Kelsey","Donghoon Chang"],"dossier_type":"paper","evidence":"primary_source_checked","id":"SYM-PAPER-2025-SP800232","keywords":["ascon","permutation","lightweight","aead","nist","standard"],"primary_url":"https://csrc.nist.gov/pubs/sp/800/232/final","status":"published","title":"Ascon-Based Lightweight Cryptography Standards for Constrained Devices","venue":"NIST SP 800-232","year":2025},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/232/final","sections":[{"content":"Standardizes Ascon-AEAD128 together with Ascon hash and XOF functions for constrained devices.","heading":"Atomic claims"},{"content":"SP 800-232 abstract and Ascon-AEAD128 specification sections.","heading":"Evidence locator"}],"status":"published","subtitle":"Meltem Sönmez Turan, Kerry McKay, Jinkeon Kang et al. · 2025","summary":"Standardizes Ascon-AEAD128 together with Ascon hash and XOF functions for constrained devices.","title":"Ascon-Based Lightweight Cryptography Standards for Constrained Devices","type":"paper","venue":"NIST SP 800-232","year":2025,"sourcePath":"data/symmetric-aead-catalog.json#SYM-PAPER-2025-SP800232"},{"evidence":"primary_source_checked","id":"SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD","keywords":["atomic-result","des","block-cipher","standard","historical","block_cipher_standards","confidentiality_to_authentication","standardization_result"],"metadata":{"claim_slug":"des-64-bit-block-cipher-standard","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["confidentiality_to_authentication"],"technical_thread":["block_cipher_standards"]},"historical_context":{"narrative":"Commercial encryption lacked a single public federal algorithm profile when FIPS 46 appeared. The document turned DES into an interoperable standard by fixing its permutation, key interface, and conformance requirements. That adoption mattered well beyond the algorithm itself: products and later mode recommendations could target one named primitive. DES nevertheless carried a 56-bit effective key and a 64-bit block, limitations that became increasingly consequential as computing improved. The atlas therefore treats this node as a historical standardization decision, not as the invention of every DES design element or a recommendation for current deployment.","prior_boundary":"Before DES, the United States had no common public federal algorithm specification for interoperable commercial data encryption.","significance_at_publication":"The decision created a shared symmetric primitive for products and later mode specifications, while also making its small effective key size a visible long-term security boundary. Its present atlas role is historical because the standard was later withdrawn and superseded.","technical_delta":"FIPS PUB 46 fixed the DES permutation, key interface, and conformance target as a federal block-cipher standard."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD","keywords":["des","block-cipher","standard","historical","block_cipher_standards","confidentiality_to_authentication","standardization_result"],"limitations":["Standardization did not invent every design element of DES and is not a present-day deployment recommendation."],"paper_id":"SYM-PAPER-1977-DES","qualifiers":["Normative 1977 federal profile; historical status is explicit."],"source_locator":{"dossier_section":"SYM-PAPER-1977-DES § Atomic claims and Evidence locator","primary_source":"FIPS PUB 46, specification and algorithm description.","primary_source_url":"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub46.pdf","status":"section_checked"},"statement":"FIPS PUB 46 normatively specifies DES as a 64-bit-block cipher with a 56-bit effective key.","statement_status":"source_normalized_statement","status":"withdrawn","title":"Federal standardization of the 56-bit-key DES block cipher","work_id":"SYM-PAPER-1977-DES"},"primaryUrl":"https://nvlpubs.nist.gov/nistpubs/Legacy/FIPS/fipspub46.pdf","sections":[],"status":"withdrawn","subtitle":"Data Encryption Standard","summary":"FIPS PUB 46 normatively specifies DES as a 64-bit-block cipher with a 56-bit effective key.","title":"Federal standardization of the 56-bit-key DES block cipher","type":"result","venue":"FIPS PUB 46","year":1977,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","keywords":["atomic-result","aes","rijndael","block-cipher","nist","standard","block_cipher_standards","software_efficiency","standardization_result"],"metadata":{"claim_slug":"aes-128-bit-block-cipher-standard","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["software_efficiency"],"technical_thread":["block_cipher_standards"]},"historical_context":{"narrative":"By the end of the DES era, exhaustive key search and the old 64-bit block made a replacement standard necessary. FIPS 197 selected the Rijndael-derived AES design and fixed a 128-bit block together with 128-, 192-, and 256-bit key profiles. This gave mode designers and implementers a common modern primitive, which is why later NIST confidentiality and AEAD recommendations can name AES as their concrete instantiation. The milestone is normative adoption rather than technical authorship of Rijndael, and AES remains only a block cipher: encryption and authentication guarantees still depend on the mode wrapped around it.","prior_boundary":"DES's 56-bit effective key and aging 64-bit block no longer provided an adequate general federal encryption standard.","significance_at_publication":"The standard established the block-cipher interface that later NIST confidentiality and AEAD recommendations instantiate. This is a standardization milestone, not a claim that the FIPS document originated Rijndael's round function or that the primitive alone supplies message authentication.","technical_delta":"FIPS 197 selected and specified the Rijndael-derived AES primitive with one block size and three normative key sizes."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","keywords":["aes","rijndael","block-cipher","nist","standard","block_cipher_standards","software_efficiency","standardization_result"],"limitations":["AES is a block cipher; confidentiality and authentication properties require a correctly used mode."],"paper_id":"SYM-PAPER-2001-AES","qualifiers":["Normative FIPS algorithm and exact key-size profiles."],"source_locator":{"dossier_section":"SYM-PAPER-2001-AES § Atomic claims and Evidence locator","primary_source":"FIPS 197 abstract and Sections 3–5.","primary_source_url":"https://csrc.nist.gov/pubs/fips/197/final","status":"section_checked"},"statement":"FIPS 197 normatively specifies AES with a 128-bit block and 128-, 192-, or 256-bit keys.","statement_status":"source_normalized_statement","status":"published","title":"Federal standardization of 128-bit-block AES with three key sizes","work_id":"SYM-PAPER-2001-AES"},"primaryUrl":"https://csrc.nist.gov/pubs/fips/197/final","sections":[],"status":"published","subtitle":"Advanced Encryption Standard (AES)","summary":"FIPS 197 normatively specifies AES with a 128-bit block and 128-, 192-, or 256-bit keys.","title":"Federal standardization of 128-bit-block AES with three key sizes","type":"result","venue":"FIPS 197","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2001-SP80038A-CBC-CONFIDENTIALITY-MODE","keywords":["atomic-result","aes","cbc","ctr","mode","nist","confidentiality_modes","confidentiality_to_authentication","standardization_result"],"metadata":{"claim_slug":"cbc-confidentiality-mode","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["confidentiality_to_authentication"],"technical_thread":["confidentiality_modes"]},"historical_context":{"narrative":"A fixed-width block cipher could not by itself specify how applications should encrypt a longer message. SP 800-38A gave CBC an interoperable answer by defining the XOR chain, an unpredictable initialization vector, complete-block processing, and inverse operations over an approved primitive. Padding formats were explicitly left outside the recommendation. CBC consequently became a durable confidentiality mode, not an authenticated-encryption scheme, so applications still needed a sound integrity construction. Its separate node also prevents one standards document from collapsing CBC into CTR: the two modes impose different sequencing, IV or counter, error-propagation, and parallel-processing contracts.","prior_boundary":"Block ciphers transformed only one fixed-size block, so interoperable multi-block encryption required a separately specified mode and IV contract.","significance_at_publication":"CBC became a widely interoperable way to encrypt variable-length data, but the document's mode boundary is important: confidentiality-only standardization did not make CBC an AEAD construction. The card is separate from CTR because their state, parallelism, error behavior, and nonce or IV obligations differ.","technical_delta":"The recommendation fixed CBC's XOR chaining, unpredictable-IV requirement, complete-block input, and decryption behavior as one independent confidentiality mode; padding remained outside the mode specification."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2001-SP80038A-CBC-CONFIDENTIALITY-MODE","keywords":["aes","cbc","ctr","mode","nist","confidentiality_modes","confidentiality_to_authentication","standardization_result"],"limitations":["CBC alone does not authenticate ciphertexts and must not be presented as AEAD."],"paper_id":"SYM-PAPER-2001-SP80038A","qualifiers":["Normative mode specification over an approved block cipher."],"source_locator":{"dossier_section":"SYM-PAPER-2001-SP80038A § Atomic claims and Evidence locator","primary_source":"SP 800-38A Sections 5.2–5.3 and 6.2, plus Appendix C for unpredictable-IV generation.","primary_source_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","status":"section_checked"},"statement":"SP 800-38A specifies CBC chaining for confidentiality under an approved block cipher and does not provide integrated ciphertext authentication.","statement_status":"source_normalized_statement","status":"published","title":"NIST specification of CBC as a confidentiality-only block-cipher mode","work_id":"SYM-PAPER-2001-SP80038A"},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","sections":[],"status":"published","subtitle":"Recommendation for Block Cipher Modes of Operation — Methods and Techniques","summary":"SP 800-38A specifies CBC chaining for confidentiality under an approved block cipher and does not provide integrated ciphertext authentication.","title":"NIST specification of CBC as a confidentiality-only block-cipher mode","type":"result","venue":"NIST SP 800-38A","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2001-SP80038A-CBC-CONFIDENTIALITY-MODE"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","keywords":["atomic-result","aes","cbc","ctr","mode","nist","confidentiality_modes","confidentiality_to_authentication","standardization_result"],"metadata":{"claim_slug":"ctr-confidentiality-mode","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["confidentiality_to_authentication"],"technical_thread":["confidentiality_modes"]},"historical_context":{"narrative":"Earlier block-cipher modes carried chaining or block-alignment behavior that constrained parallel processing. SP 800-38A standardized a different interface: encrypt distinct counter values, then XOR the resulting keystream with any-length plaintext. Independent block-cipher calls made encryption parallelizable and avoided padding the last partial block. More importantly for the later AEAD story, this counter rail could be combined with authentication, as CCM and GCM eventually did. CTR itself still authenticates nothing, and reusing a counter under one key repeats keystream material. Its backbone role therefore marks a reusable confidentiality component, not a complete data-protection endpoint.","prior_boundary":"Conventional chaining modes serialized parts of encryption and imposed block-aligned processing behavior around a primitive.","significance_at_publication":"CTR became a reusable encryption rail for later AEAD specifications including CCM and GCM. Its standardization did not itself add integrity: counter uniqueness remains a caller-level security condition, and malleability remains unless a separate authentication mechanism is composed correctly.","technical_delta":"The recommendation standardized a counter-based confidentiality mode whose block-cipher calls can be parallelized and whose final data block need not be padded."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","keywords":["aes","cbc","ctr","mode","nist","confidentiality_modes","confidentiality_to_authentication","standardization_result"],"limitations":["CTR alone is malleable and provides no ciphertext authenticity."],"paper_id":"SYM-PAPER-2001-SP80038A","qualifiers":["Counter blocks must be distinct under one key."],"source_locator":{"dossier_section":"SYM-PAPER-2001-SP80038A § Atomic claims and Evidence locator","primary_source":"SP 800-38A Sections 5.2 and 6.5, plus Appendix B for counter-block uniqueness.","primary_source_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","status":"section_checked"},"statement":"SP 800-38A specifies CTR mode by encrypting distinct counter blocks to form a keystream that is XORed with plaintext.","statement_status":"source_normalized_statement","status":"published","title":"NIST specification of parallel counter-mode confidentiality","work_id":"SYM-PAPER-2001-SP80038A"},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/a/final","sections":[],"status":"published","subtitle":"Recommendation for Block Cipher Modes of Operation — Methods and Techniques","summary":"SP 800-38A specifies CTR mode by encrypting distinct counter blocks to form a keystream that is XORed with plaintext.","title":"NIST specification of parallel counter-mode confidentiality","type":"result","venue":"NIST SP 800-38A","year":2001,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2004-CCM-CCM-CTR-CBC-MAC-AEAD","keywords":["atomic-result","ccm","aead","ctr","cbc-mac","nist","composed_aead","confidentiality_to_authentication","standardization_result"],"metadata":{"claim_slug":"ccm-ctr-cbc-mac-aead","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["confidentiality_to_authentication"],"technical_thread":["composed_aead"]},"historical_context":{"narrative":"NIST's first confidentiality-mode recommendation left integrity to a separate mechanism. SP 800-38C closed that interface gap for one concrete profile by formatting the nonce, message, and associated data for CBC-MAC, then using CTR to encrypt both plaintext and authentication value. The result was a standardized AEAD contract rather than an implication that CBC or CTR alone had become authenticating. CCM's serial MAC computation and two-pass structure also define a different engineering point from GCM's polynomial authenticator. This node records the normative composition and its input rules; it does not attribute the invention of either underlying component to the standards document.","prior_boundary":"NIST's earlier confidentiality modes encrypted data but did not expose one standardized interface that also authenticated ciphertext and associated context.","significance_at_publication":"The recommendation established an interoperable nonce-based AEAD profile without claiming that confidentiality modes alone authenticate data. Its two-pass structure and formatting contract distinguish it from GCM. The atlas records the normative composition, not an assertion that SP 800-38C invented CTR or CBC-MAC.","technical_delta":"CCM composed two established block-cipher mechanisms: CBC-MAC authenticates formatted inputs and CTR encrypts the plaintext and protects the tag."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2004-CCM-CCM-CTR-CBC-MAC-AEAD","keywords":["ccm","aead","ctr","cbc-mac","nist","composed_aead","confidentiality_to_authentication","standardization_result"],"limitations":["CCM is not misuse-resistant to nonce repetition and is not a one-pass construction."],"paper_id":"SYM-PAPER-2004-CCM","qualifiers":["Nonce uniqueness, supported tag lengths, and formatting follow SP 800-38C."],"source_locator":{"dossier_section":"SYM-PAPER-2004-CCM § Atomic claims and Evidence locator","primary_source":"SP 800-38C Sections 1, 5, and 6.","primary_source_url":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","status":"section_checked"},"statement":"SP 800-38C specifies CCM authenticated encryption by combining counter-mode encryption with CBC-MAC over formatted plaintext and associated data.","statement_status":"source_normalized_statement","status":"published","title":"NIST specification of CCM's CTR-plus-CBC-MAC AEAD composition","work_id":"SYM-PAPER-2004-CCM"},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","sections":[],"status":"published","subtitle":"Recommendation for Block Cipher Modes of Operation — The CCM Mode for Authentication and Confidentiality","summary":"SP 800-38C specifies CCM authenticated encryption by combining counter-mode encryption with CBC-MAC over formatted plaintext and associated data.","title":"NIST specification of CCM's CTR-plus-CBC-MAC AEAD composition","type":"result","venue":"NIST SP 800-38C","year":2004,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2004-CCM-CCM-CTR-CBC-MAC-AEAD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","keywords":["atomic-result","gcm","aead","ctr","universal-hash","nist","composed_aead","confidentiality_to_authentication","software_efficiency","standardization_result"],"metadata":{"claim_slug":"gcm-counter-mode-plus-universal-hash-aead","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["confidentiality_to_authentication","software_efficiency"],"technical_thread":["composed_aead"]},"historical_context":{"narrative":"CCM supplied standardized authenticated encryption, but its CBC-MAC pass did not match every high-throughput parallel workload. SP 800-38D profiled GCM by pairing CTR encryption with GHASH, a polynomial authenticator over ciphertext and associated data; it also separated the authentication-only GMAC interface. This standardization made a parallelizable AEAD widely interoperable without making NIST the originator of the underlying proposal. GCM's speed and adoption came with a sharp operational contract: IV uniqueness under a key is security-critical, and repetition can damage privacy and forgery resistance at once. That failure mode later motivated the distinct GCM-SIV branch.","prior_boundary":"CCM provided standardized AEAD but used a serial CBC-MAC pass, leaving demand for a highly parallel authenticated-encryption profile.","significance_at_publication":"The recommendation fixed an interoperable, parallelizable AEAD construction that became a central deployment profile. Its historical significance is standardization and engineering suitability, not invention by the NIST document. The nonce contract remains essential because repeating a GCM IV under one key can compromise both confidentiality and authentication.","technical_delta":"GCM paired parallel counter-mode encryption with binary-field universal hashing over ciphertext and associated data."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","keywords":["gcm","aead","ctr","universal-hash","nist","composed_aead","confidentiality_to_authentication","software_efficiency","standardization_result"],"limitations":["GCM does not provide bounded nonce-misuse resistance."],"paper_id":"SYM-PAPER-2007-GCM","qualifiers":["GCM and GMAC are distinct interfaces within SP 800-38D; this card covers GCM AEAD."],"source_locator":{"dossier_section":"SYM-PAPER-2007-GCM § Atomic claims and Evidence locator","primary_source":"SP 800-38D abstract and Sections 5–7.","primary_source_url":"https://csrc.nist.gov/pubs/sp/800/38/d/final","status":"section_checked"},"statement":"SP 800-38D specifies GCM authenticated encryption by combining counter-mode encryption with GHASH polynomial authentication over ciphertext and associated data.","statement_status":"source_normalized_statement","status":"published","title":"NIST specification of GCM's CTR-plus-GHASH AEAD composition","work_id":"SYM-PAPER-2007-GCM"},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/38/d/final","sections":[],"status":"published","subtitle":"Recommendation for Block Cipher Modes of Operation — Galois/Counter Mode (GCM) and GMAC","summary":"SP 800-38D specifies GCM authenticated encryption by combining counter-mode encryption with GHASH polynomial authentication over ciphertext and associated data.","title":"NIST specification of GCM's CTR-plus-GHASH AEAD composition","type":"result","venue":"NIST SP 800-38D","year":2007,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER","keywords":["atomic-result","chacha","stream-cipher","arx","stream_aead","software_efficiency","construction"],"metadata":{"claim_slug":"chacha-arx-stream-cipher","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["software_efficiency"],"technical_thread":["stream_aead"]},"historical_context":{"narrative":"Salsa20 had already demonstrated the appeal of simple add-rotate-XOR operations for software stream encryption. ChaCha revised the quarter-round and alternated column and diagonal updates to improve diffusion while preserving the ARX design style. The paper's contribution is this family of stream-cipher transformations and the resulting keystream primitive. A decade later, RFC 8439 selected ChaCha20 and paired it with Poly1305, but that protocol profile is a separate contribution with its own nonce, formatting, and tag rules. ChaCha by itself offers no authentication, so its software-oriented architecture must not be read as an AEAD guarantee.","prior_boundary":"Salsa20 had established an ARX stream-cipher family, but its round structure was still open to variants with faster diffusion and competitive software performance.","significance_at_publication":"The design supplied the stream primitive later profiled as ChaCha20 and composed with Poly1305. This atomic contribution is the cipher architecture, not the later AEAD or IETF wire format; keeping those objects separate prevents software efficiency of a primitive from being mistaken for authenticated encryption.","technical_delta":"ChaCha changed the quarter-round and the ordering of column and diagonal updates while retaining a simple ARX state transformation."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER","keywords":["chacha","stream-cipher","arx","stream_aead","software_efficiency","construction"],"limitations":["ChaCha alone encrypts a keystream and does not authenticate ciphertext or associated data."],"paper_id":"SYM-PAPER-2008-CHACHA","qualifiers":["Stream-cipher design; the map does not normalize every reduced-round variant."],"source_locator":{"dossier_section":"SYM-PAPER-2008-CHACHA § Atomic claims and Evidence locator","primary_source":"Author-hosted paper, design and round-function sections.","primary_source_url":"https://cr.yp.to/chacha/chacha-20080128.pdf","status":"section_checked"},"statement":"ChaCha revises Salsa20's add-rotate-XOR round function and state update to define a family of stream ciphers with changed diffusion behavior.","statement_status":"source_normalized_statement","status":"published","title":"ChaCha's revised ARX round function for software stream encryption","work_id":"SYM-PAPER-2008-CHACHA"},"primaryUrl":"https://cr.yp.to/chacha/chacha-20080128.pdf","sections":[],"status":"published","subtitle":"ChaCha, a Variant of Salsa20","summary":"ChaCha revises Salsa20's add-rotate-XOR round function and state update to define a family of stream ciphers with changed diffusion behavior.","title":"ChaCha's revised ARX round function for software stream encryption","type":"result","venue":"SASC 2008","year":2008,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2008-SIV-AES-SIV-NONCE-MISUSE-RESISTANT-AEAD","keywords":["atomic-result","siv","misuse-resistant","aead","aes","rfc","misuse_resistance","nonce_misuse","standardization_result"],"metadata":{"claim_slug":"aes-siv-nonce-misuse-resistant-aead","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["nonce_misuse"],"technical_thread":["misuse_resistance"]},"historical_context":{"narrative":"The SIV construction already existed in the research literature, but implementations still needed one exact AES profile. RFC 5297 supplied it by instantiating S2V with AES-CMAC, using the synthetic value for AES-CTR, accepting a vector of associated-data strings, and fixing key sizes and AEAD identifiers. The document explicitly credits Rogaway and Shrimpton for SIV, so this node represents interoperable profiling rather than invention of misuse-resistant authenticated encryption. Its contract remains bounded: repeated nonces retain authenticity but can reveal equality for repeated plaintext and associated data, and encryption requires two passes instead of online release.","prior_boundary":"Rogaway and Shrimpton had already specified the SIV design, but protocol use still needed an interoperable AES instantiation, vector-associated-data interface, algorithm identifiers, and testable encoding rules.","significance_at_publication":"The Informational RFC made deterministic and nonce-misuse-resistant SIV available as a precise AES profile while explicitly crediting the earlier research design and retaining its equality-leakage and two-pass limits.","technical_delta":"RFC 5297 fixed SIV as an AES-CMAC-based S2V computation followed by AES-CTR, with concrete key sizes, multiple associated-data strings, and IANA AEAD identifiers."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2008-SIV-AES-SIV-NONCE-MISUSE-RESISTANT-AEAD","keywords":["siv","misuse-resistant","aead","aes","rfc","misuse_resistance","nonce_misuse","standardization_result"],"limitations":["Repeated inputs can reveal equality; nonce misuse resistance is not unlimited misuse safety."],"paper_id":"SYM-PAPER-2008-SIV","qualifiers":["Misuse resistance is bounded and follows the SIV security contract."],"source_locator":{"dossier_section":"SYM-PAPER-2008-SIV § Atomic claims and Evidence locator","primary_source":"RFC 5297 Sections 1.3.2, 2.2, and 2.6.","primary_source_url":"https://www.rfc-editor.org/rfc/rfc5297.html","status":"section_checked"},"statement":"RFC 5297 specifies AES-SIV, which computes a synthetic IV with S2V and then applies AES-CTR to provide deterministic or nonce-based authenticated encryption.","statement_status":"source_normalized_statement","status":"published","title":"Informational RFC profile for AES-SIV deterministic and nonce-misuse-resistant AEAD","work_id":"SYM-PAPER-2008-SIV"},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc5297.html","sections":[],"status":"published","subtitle":"Synthetic Initialization Vector (SIV) Authenticated Encryption Using AES","summary":"RFC 5297 specifies AES-SIV, which computes a synthetic IV with S2V and then applies AES-CTR to provide deterministic or nonce-based authenticated encryption.","title":"Informational RFC profile for AES-SIV deterministic and nonce-misuse-resistant AEAD","type":"result","venue":"RFC 5297","year":2008,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2008-SIV-AES-SIV-NONCE-MISUSE-RESISTANT-AEAD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD","keywords":["atomic-result","ascon","permutation","lightweight","aead","lightweight_permutations","lightweight_standardization","construction"],"metadata":{"claim_slug":"ascon-permutation-based-lightweight-aead","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["lightweight_standardization"],"technical_thread":["lightweight_permutations"]},"historical_context":{"narrative":"Many established AEAD profiles were shaped by desktop, server, or hardware-assisted AES workloads rather than the area and energy limits of small embedded devices. The initial Ascon v1 submission organized initialization, associated-data absorption, encryption, and finalization around one 320-bit permutation and a keyed duplex-style state. That architecture supplied a nonce-based AEAD family intentionally aimed at lightweight implementation. It is the technical predecessor of NIST's later Ascon-AEAD128 profile, but the 2014 submission and 2025 standard are not byte-identical. The design target also is not a universal benchmark result: performance depends on the exact variant, platform, implementation, and comparator.","prior_boundary":"AES-based and high-throughput software AEAD designs did not represent every area and energy tradeoff encountered in small embedded devices.","significance_at_publication":"The architecture established the technical construction later selected and profiled by NIST for constrained devices. This card records the construction rather than the later standardization decision, and it treats lightweight orientation as a design target rather than converting unnormalized implementation results into a universal performance ranking.","technical_delta":"Ascon used one small permutation for initialization, associated-data absorption, encryption, and finalization, with parameters chosen for lightweight implementation."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD","keywords":["ascon","permutation","lightweight","aead","lightweight_permutations","lightweight_standardization","construction"],"limitations":["The construction is not nonce-misuse-resistant and no cross-platform benchmark ranking is inferred."],"paper_id":"SYM-PAPER-2014-ASCON","qualifiers":["Nonce-based permutation AEAD; lightweight is an implementation target."],"source_locator":{"dossier_section":"SYM-PAPER-2014-ASCON § Atomic claims and Evidence locator","primary_source":"Ascon v1 initial CAESAR submission dated 2014-03-15, Sections 1.1–1.4; later submissions and SP 800-232 are distinct versions.","primary_source_url":"https://ascon.iaik.tugraz.at/files/ascon.pdf","status":"section_checked"},"statement":"The initial Ascon v1 submission defines nonce-based authenticated encryption around one 320-bit permutation, a keyed duplex-style state, and domain-separated processing phases.","statement_status":"source_normalized_statement","status":"published","title":"Ascon permutation-duplex nonce AEAD family for constrained environments","work_id":"SYM-PAPER-2014-ASCON"},"primaryUrl":"https://ascon.iaik.tugraz.at/files/ascon.pdf","sections":[],"status":"published","subtitle":"Ascon v1 — Submission to the CAESAR Competition","summary":"The initial Ascon v1 submission defines nonce-based authenticated encryption around one 320-bit permutation, a keyed duplex-style state, and domain-separated processing phases.","title":"Ascon permutation-duplex nonce AEAD family for constrained environments","type":"result","venue":"CAESAR round-one submission","year":2014,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2018-RFC8439-CHACHA20-POLY1305-AEAD","keywords":["atomic-result","chacha20","poly1305","aead","rfc","stream-cipher","stream_aead","confidentiality_to_authentication","software_efficiency","standardization_result"],"metadata":{"claim_slug":"chacha20-poly1305-aead","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["confidentiality_to_authentication","software_efficiency"],"technical_thread":["stream_aead"]},"historical_context":{"narrative":"ChaCha and Poly1305 were already independent cryptographic components, yet protocol developers still needed one unambiguous way to derive the one-time MAC key, encode associated data, pad fields, increment counters, and serialize the tag. RFC 8439 supplied that complete IETF profile with a 256-bit key, 96-bit nonce, and 128-bit authenticator. Its importance lies in interoperable composition and deployment, not in claiming invention of either primitive. The resulting AEAD offers a strong software-oriented alternative to AES profiles, but only under its caller contract: nonces must not repeat for one key, and receivers must authenticate before exposing plaintext.","prior_boundary":"ChaCha and Poly1305 existed as separate primitives, but protocol implementations required one interoperable key, nonce, formatting, padding, and tag-generation contract.","significance_at_publication":"Its contribution is an interoperable protocol profile and composition specification, not invention of ChaCha or Poly1305. The profile supplied a software-oriented alternative to AES-based AEAD, while retaining a strict nonce-uniqueness requirement and a verification-before-release obligation for received plaintext.","technical_delta":"The RFC fixed the IETF ChaCha20-Poly1305 AEAD data layout and derived one-time authentication key procedure."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2018-RFC8439-CHACHA20-POLY1305-AEAD","keywords":["chacha20","poly1305","aead","rfc","stream-cipher","stream_aead","confidentiality_to_authentication","software_efficiency","standardization_result"],"limitations":["Nonce repetition under one key violates the construction's security contract."],"paper_id":"SYM-PAPER-2018-RFC8439","qualifiers":["IETF profile with fixed key, nonce, and tag dimensions."],"source_locator":{"dossier_section":"SYM-PAPER-2018-RFC8439 § Atomic claims and Evidence locator","primary_source":"RFC 8439 abstract and Sections 2.3–2.8.","primary_source_url":"https://www.rfc-editor.org/rfc/rfc8439.html","status":"section_checked"},"statement":"RFC 8439 specifies the ChaCha20 stream-cipher profile, Poly1305 one-time authenticator use, and their AEAD composition with a 256-bit key, 96-bit nonce, and 128-bit tag.","statement_status":"source_normalized_statement","status":"published","title":"IETF profile of ChaCha20-Poly1305 with a 96-bit nonce","work_id":"SYM-PAPER-2018-RFC8439"},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc8439.html","sections":[],"status":"published","subtitle":"ChaCha20 and Poly1305 for IETF Protocols","summary":"RFC 8439 specifies the ChaCha20 stream-cipher profile, Poly1305 one-time authenticator use, and their AEAD composition with a 256-bit key, 96-bit nonce, and 128-bit tag.","title":"IETF profile of ChaCha20-Poly1305 with a 96-bit nonce","type":"result","venue":"RFC 8439","year":2018,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2018-RFC8439-CHACHA20-POLY1305-AEAD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2019-GCMSIV-AES-GCM-SIV-MISUSE-RESISTANT-AEAD","keywords":["atomic-result","gcm-siv","siv","misuse-resistant","aead","rfc","misuse_resistance","nonce_misuse","standardization_result"],"metadata":{"claim_slug":"aes-gcm-siv-misuse-resistant-aead","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["nonce_misuse"],"technical_thread":["misuse_resistance"]},"historical_context":{"narrative":"Research on GCM-SIV and nonce-based key derivation preceded the final protocol profile. RFC 8452 consolidated that line into two testable AEAD algorithms, fixing per-record key derivation, POLYVAL processing, counter layout, limits, and vectors for 128- and 256-bit keys. Its role in the atlas is CFRG profiling, not first invention of the underlying idea. The resulting contract is materially safer than GCM under accidental nonce repetition, but still bounded: equal plaintexts can be exposed, usage limits depend on message size and repeat counts, and the RFC recommends randomly generated nonces rather than deliberate reuse.","prior_boundary":"AES-GCM-SIV had been analyzed in research papers, but implementers needed a stable CFRG profile with exact record-key derivation, POLYVAL encoding, counter layout, limits, and test vectors.","significance_at_publication":"The Informational RFC turned the analyzed construction into a consensus, testable profile and documented bounded behavior under accidental nonce repetition without presenting reuse as consequence-free.","technical_delta":"RFC 8452 fixed two AEAD algorithm identifiers and their 128- or 256-bit-key procedures, deriving per-record authentication and encryption keys before computing a POLYVAL-based synthetic IV."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2019-GCMSIV-AES-GCM-SIV-MISUSE-RESISTANT-AEAD","keywords":["gcm-siv","siv","misuse-resistant","aead","rfc","misuse_resistance","nonce_misuse","standardization_result"],"limitations":["Nonce reuse can still reveal equality and degrades guarantees; it is not consequence-free."],"paper_id":"SYM-PAPER-2019-GCMSIV","qualifiers":["Security bounds and message limits follow RFC 8452's exact profile."],"source_locator":{"dossier_section":"SYM-PAPER-2019-GCMSIV § Atomic claims and Evidence locator","primary_source":"RFC 8452 Abstract, Sections 3–6, and Section 9 security considerations and usage bounds.","primary_source_url":"https://www.rfc-editor.org/rfc/rfc8452.html","status":"section_checked"},"statement":"RFC 8452 specifies AES-GCM-SIV, deriving per-record keys and a synthetic IV with POLYVAL before counter-mode encryption.","statement_status":"source_normalized_statement","status":"published","title":"CFRG profile of AES-GCM-SIV with per-record keys and bounded nonce-reuse resistance","work_id":"SYM-PAPER-2019-GCMSIV"},"primaryUrl":"https://www.rfc-editor.org/rfc/rfc8452.html","sections":[],"status":"published","subtitle":"AES-GCM-SIV — Nonce Misuse-Resistant Authenticated Encryption","summary":"RFC 8452 specifies AES-GCM-SIV, deriving per-record keys and a synthetic IV with POLYVAL before counter-mode encryption.","title":"CFRG profile of AES-GCM-SIV with per-record keys and bounded nonce-reuse resistance","type":"result","venue":"RFC 8452","year":2019,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2019-GCMSIV-AES-GCM-SIV-MISUSE-RESISTANT-AEAD"},{"evidence":"primary_source_checked","id":"SYM-RESULT-2025-SP800232-ASCON-AEAD128-NORMATIVE-STANDARD","keywords":["atomic-result","ascon","permutation","lightweight","aead","nist","standard","lightweight_permutations","lightweight_standardization","standardization_result"],"metadata":{"claim_slug":"ascon-aead128-normative-standard","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["lightweight_standardization"],"technical_thread":["lightweight_permutations"]},"historical_context":{"narrative":"After the Ascon family had been designed and selected, implementers still needed a single normative profile with fixed parameters, byte ordering, interfaces, and algorithm steps. SP 800-232 filled that role for Ascon-AEAD128 in constrained-device settings. The publication marks adoption and interoperability; the underlying permutation and AEAD architecture belong to the earlier construction record. NIST also standardized Ascon-based hash and XOF functions in the same document, but they answer a different cryptographic task and remain outside this topic's declared boundary. Keeping only the AEAD contribution prevents one standard from collapsing several independent technical objects into a compound node.","prior_boundary":"Ascon already existed as a permutation-based construction and had passed selection, but interoperable deployment required a fixed NIST algorithm, byte ordering, interfaces, and parameter profile.","significance_at_publication":"The contribution is the normative adoption and exact profile, not invention of Ascon's permutation or AEAD architecture. Although the document also standardizes hash and XOF functions, this topic card deliberately covers only Ascon-AEAD128 because standalone hashing lies outside the declared symmetric-encryption and AEAD scope.","technical_delta":"SP 800-232 selected one concrete AEAD profile and specified its initialization, processing, finalization, and input-output conventions."},"historical_context_status":"curator_synthesis","id":"SYM-RESULT-2025-SP800232-ASCON-AEAD128-NORMATIVE-STANDARD","keywords":["ascon","permutation","lightweight","aead","nist","standard","lightweight_permutations","lightweight_standardization","standardization_result"],"limitations":["The standard does not imply nonce-misuse resistance or universal superiority on all constrained platforms."],"paper_id":"SYM-PAPER-2025-SP800232","qualifiers":["Normative Ascon-AEAD128 profile only; hash/XOF siblings remain out of scope."],"source_locator":{"dossier_section":"SYM-PAPER-2025-SP800232 § Atomic claims and Evidence locator","primary_source":"SP 800-232 abstract and Ascon-AEAD128 specification sections.","primary_source_url":"https://csrc.nist.gov/pubs/sp/800/232/final","status":"section_checked"},"statement":"SP 800-232 normatively specifies Ascon-AEAD128 for authenticated encryption in constrained-device settings.","statement_status":"source_normalized_statement","status":"published","title":"NIST standardization of the Ascon-AEAD128 lightweight profile","work_id":"SYM-PAPER-2025-SP800232"},"primaryUrl":"https://csrc.nist.gov/pubs/sp/800/232/final","sections":[],"status":"published","subtitle":"Ascon-Based Lightweight Cryptography Standards for Constrained Devices","summary":"SP 800-232 normatively specifies Ascon-AEAD128 for authenticated encryption in constrained-device settings.","title":"NIST standardization of the Ascon-AEAD128 lightweight profile","type":"result","venue":"NIST SP 800-232","year":2025,"sourcePath":"data/symmetric-aead-catalog.json#SYM-RESULT-2025-SP800232-ASCON-AEAD128-NORMATIVE-STANDARD"}],"propertyAssertions":[{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-002D69A45DBF17","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"NIST SP 800-38C"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-009799B63BB622","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"random-access-keystream"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-01039363E0E9CC","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"feistel"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-028D37E405098D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"128 bits"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-02BB4F33AA646D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"stream_cipher"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-03215ED5A9174B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"arx"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-03C29C206C3655","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"confidentiality"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-06DB4B876B7D66","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"AEAD"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-0DF9A47B271001","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"independent block calls"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-0E2600EF428703","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"associated-data"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-0F766B353ECECD","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"yes"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-135E70077A0848","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"yes"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-13705D69F6E744","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"256 bits"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-15B21B3A50FD90","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"96 bits recommended; other lengths are processed by GHASH"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-186D89075BEA2E","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"profile-selected up to 128 bits with NIST constraints"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-190E9DFD6C7154","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"yes"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-1979B623972A7F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"no; nonce repetition violates the security contract"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-1B26591EAE543F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"byte/bit stream derived from 128-bit blocks"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-1BA24C8D4AF41A","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"lightweight-aead"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-1DB271615B39AF","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"block_cipher"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-1F2D52A04EB2B1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"not applicable"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-21F08FB87E30F3","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"NIST SP 800-38A; confidentiality only"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-26302C5EF67AE2","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"nonce-misuse-resistance"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-273DFCBF8A7C43","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"synthetic_iv_plus_counter"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-291F45CBCE180E","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"associated-data"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-2B60C13813A41B","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"unpredictable 128-bit IV for encryption"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-2F82E4F56F9BB1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"64 bits"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-30EDC16E5E8E8A","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"constrained-device-profile"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-3408EFA8B3BEE3","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"integrity"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-355756A4A4824C","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"block_cipher"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-36551CB6E8E5AF","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"RFC 8452 (Informational)"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-371BA5C4610BEE","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"confidentiality_mode"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-3F833E3A67A92F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"stream_cipher_plus_one_time_mac"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-432D3989B80E2C","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"associated-data"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-43938A091A7F69","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"yes for CTR and GHASH evaluation strategies"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-439F1560559362","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"yes"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-46633BF566FBD1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"yes; vector of associated-data strings"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-46A33153D65BE6","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"AEAD"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-4BD0909A45B931","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"counter blocks must be unique under a key"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-4D6978599565AA","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"block-permutation"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-501FD05B2EA325","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"withdrawn and superseded; historical only"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-50E7C0E3F63F40","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"AES key size"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-51E0AB625BB69A","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"no; tag/synthetic IV is computed before encryption"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-527438FAC4CF48","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"misuse_resistant_AEAD"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-54CAE923CFF8AB","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"POLYVAL and CTR admit parallel implementation strategies"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-555D615E71EEB9","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"128-bit AES and GHASH blocks"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-55C722D114925F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"authenticated_encryption"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-5A0A03AC5F0D5C","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"synthetic_iv"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-5E4066D2ABE03B","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"ctr_plus_cbc_mac"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-5EF750C156E4CF","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"parallel-processing"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-5F20586EC789AF","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"AES key size"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-601CEE0205044F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"96-bit nonce must be unique under a key"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-60281AF59B55EB","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"authenticated_encryption"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-61EE4BD5AA2AF4","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"symmetric_block_cipher"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-646F7F0809F85A","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"nonce must be unique under a key"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-6742D4282F59CB","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"encryption no; decryption block calls yes"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-6784B89401CD5E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"64 bits in the original family presentation"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-6AC5AB3F84DEC8","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"authenticated_encryption"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-6BDA2B6AAF1CD2","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"optional; uniqueness improves privacy but repetition is tolerated with bounded leakage"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-6C2FD7F5BB783D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"profile-defined counter block totaling 128 bits"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-6D895AA23AC292","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"integrity"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-6F0092D22F0B7D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"NIST SP 800-38A; confidentiality only"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-72C0CB3CC32B82","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"yes"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-73282B4DC41570","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"128-bit AES blocks"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-74EC8C0BF2B167","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"AES key size"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-768FA67BAE1226","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"substitution_permutation_network"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-77BCDF38DDD6BB","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"permutation_based_duplex"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-780FF1687CFF4C","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"96 bits"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-7AC3B49647F469","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"no"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-7B0718ACC17C0D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"no"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-7B775DB5BAF172","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"128 bits"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-7E1893DFE4E00B","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"parallel-block-processing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-7E4CBD8B055641","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"software-portability"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-7E61ECA612D5C0","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"confidentiality"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-80A9FC2BCA0A8B","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"AEAD"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-8253A3140FE591","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"optional associated-data component; 128-bit random nonce recommended when used"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-853FB2DB4C6739","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"no; nonce reuse repeats the stream and one-time authenticator key"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-869E167398A2CE","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"associated-data"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-872A58EC6EA3C6","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"none"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-8828AE69552C8F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"no"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-89C354D288750A","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"no; the standardized AEAD is nonce respecting"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-8B04B672581B09","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"associated-data"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-90425E2A4194F5","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"symmetric_encryption_mode"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-90AEBD4B68B2A8","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"parallel-processing"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-91BACBD11C29AA","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"confidentiality_mode"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-92C009449A2AA7","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"authenticated_encryption"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-94E3AC7CC52012","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"symmetric_block_cipher"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-980D1DE7631285","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"no; IV failure can reveal relations and the mode provides no integrity"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-9935B523B8782F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"128 / 192 / 256 bits"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-9A0625816C2BDA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"symmetric_stream_cipher"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-9A23F70E321BCF","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"not applicable"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-9B4DCD27E6BA62","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"yes"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-9BAB4B9F4A8CF4","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"128-bit IV"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-9EEDA40BF9EEC6","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"96-bit nonce; uniqueness is recommended but accidental repetition has bounded degradation"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-A19FC4EDF8712F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"no; repeated IVs can catastrophically damage confidentiality and authentication"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-A1C399809C489B","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"misuse_resistant_AEAD"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-A29CEF9A55AF3A","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"CTR portion yes; CBC-MAC portion no"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-A531906CDFF13D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"counter_plus_galois_hash"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-A5A2CE490F3DDF","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"confidentiality"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-A93F66D95873D2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"no; repeated keystream exposes plaintext relations"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-A98487E76D8720","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"block-function calls can be parallelized"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-AA28E29AC9B542","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"symmetric_encryption_mode"},{"dimension":"object_type","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-AA48B7C6664688","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"lightweight_AEAD"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-AA6984FF32A219","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"256 / 384 / 512 bits split across S2V and CTR"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-AA88B8A2F1B135","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"no; keystream reuse exposes plaintext relations"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-AB32998CFADECA","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"deterministic-aead"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-B052C0E83AD4F8","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"one block at a time"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-B0851E20C85605","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"not applicable"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-B0BD81068B27B5","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"yes for accidental repetition within documented limits; equality leakage remains"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-B1AD5AFAE4B533","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"not applicable to the primitive"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-B36C51DF9574C4","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"128-bit synthetic IV"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-B467F5E9904F5D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"yes; repeated inputs reveal equality but do not cause GCM-style key recovery"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-B87D7C44754323","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"authenticated_encryption"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-B9FB59598DFB76","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"research construction; RFC 8439 defines the IETF ChaCha20 profile"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-BAB83DEC04DD10","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"incremental processing; plaintext release should follow tag verification"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-BB31952C3DCD70","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"128 or 256 bits"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-BCABAAD97254CD","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"variable-length-confidentiality"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-BE1378F3D06A0A","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"nonce-misuse-resistance"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-BE5342A41D4185","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"128-bit nonce must be unique under a key"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-C2E35CA2454E9B","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"integrity"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-C2F43A445E7B0E","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"not applicable; mode-defined"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-C696BE6F215533","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"no"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-C8EE963A251AC0","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"128 bits"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-C9C7CBD7BCBDE9","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"128-bit AES blocks"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-CAFF46BD8D5423","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"NIST SP 800-38D"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-CE49D463F832C9","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"counter_mode"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-CF2B9F40FA0DDA","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"128 bits"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-D1F3DF6F425543","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"yes for computation; plaintext release should follow tag verification"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-D566918D8C7554","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"56–104 bits (7–13 octets)"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-D5EA18E75E19BD","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"32–128 bits in permitted even-byte increments"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-D7EC6781FB42BB","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"software-oriented-stream-encryption"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-D85C49FA275774","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"RFC 5297 (Informational)"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-D9AEB6736A28CE","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"no; CBC-MAC and message length precede CTR encryption"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-DBB7195FF41C3D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"128 bits"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-DD96A35629D71A","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"NIST SP 800-232"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-DDF30A88929419","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"associated-data-vector"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-DE189E15969546","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"not applicable to the primitive"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-DEEB0B692378BA","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"authenticated_encryption"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-DF28C8704AA63B","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"RFC 8439 (Informational CFRG consensus)"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-DFEE33D5C71BFC","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"no"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-E02C524A8D7F1F","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"512-bit ChaCha20 blocks; 16-byte Poly1305 processing"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-E037BCD8BBCCCF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"none"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-E1DE512D775805","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"random-access-confidentiality"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-E1E02FA6D05292","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"AES key size"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-E334186FA97B38","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"independent block calls"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-E3483E743540D2","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"permutation dependency is sequential within a message"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-E425D805F6F73D","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"56-bit effective key"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-E42FDC7D3BC362","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"128 bits"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-E69345523286C4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"512-bit keystream blocks"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-E70E17461C15E1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"one block at a time"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-E7351442488CFD","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"nonce/counter input must not repeat under a key"},{"dimension":"nonce_requirement","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2007-GCM.md","id":"SYM-PROP-EF68A9A42E52A9","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2007-GCM","value":"IV uniqueness is critical; 96 bits is the recommended interoperable length"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-F0FAB3D229D454","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"yes"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-F11D9E8A102E14","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"yes"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-F32968066B858B","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"not applicable"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2025-ASCONAEAD128.md","id":"SYM-PROP-F5435FD28485A1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2025-ASCONAEAD128","value":"128-bit rate over a 320-bit permutation state"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-F54EBA10E2CBF6","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"128-bit data blocks; padding, when needed, is outside the mode specification"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-F56A1F3D5F48E5","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"standardized-primitive"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2018-CHACHAPOLY.md","id":"SYM-PROP-F5E8254A8FA852","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2018-CHACHAPOLY","value":"ChaCha20 blocks yes; Poly1305 is incremental"},{"dimension":"key_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-CHACHA.md","id":"SYM-PROP-F603F334946148","review_status":"primary_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-CHACHA","value":"256 bits in the primary profile"},{"dimension":"associated_data","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2004-CCM.md","id":"SYM-PROP-F6207DC88DD388","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2004-CCM","value":"yes"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-F6CEBCDD6D4BA7","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"cipher_block_chaining"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-F7C9898A65FFF5","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"no; synthetic IV is computed before CTR encryption"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-1977-DES.md","id":"SYM-PROP-F7D6A527AA296F","review_status":"scheme_declared","scope":"construction","subject_id":"SYM-CONSTRUCTION-1977-DES","value":"block-permutation"},{"dimension":"normative_status","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-F999C9DC840A27","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"FIPS 197"},{"dimension":"block_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-FA2243BE508FB4","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"128-bit AES/POLYVAL blocks"},{"dimension":"online","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCBC.md","id":"SYM-PROP-FCD429685D7A53","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCBC","value":"encryption is sequential"},{"dimension":"parallelizable","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2008-AESSIV.md","id":"SYM-PROP-FD0F4370367677","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2008-AESSIV","value":"CTR phase yes; S2V/CMAC chain limited"},{"dimension":"tag_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AESCTR.md","id":"SYM-PROP-FF4BB2FAA9D0F1","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AESCTR","value":"none"},{"dimension":"misuse_resistance","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2001-AES.md","id":"SYM-PROP-FF6735C90BD914","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2001-AES","value":"not applicable; mode-defined"},{"dimension":"nonce_size","evidence_ref":"knowledge/primitives/symmetric-aead/schemes/SYM-CONSTRUCTION-2019-GCMSIV.md","id":"SYM-PROP-FF7DE853CACD98","review_status":"normative_source_reviewed","scope":"construction","subject_id":"SYM-CONSTRUCTION-2019-GCMSIV","value":"96 bits"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"ChaCha ARX stream cipher","lane_rationale":"The source introduces the revised ARX quarter-round and column/diagonal update mechanism of the ChaCha family; changed diffusion is a construction delta, not a standard-adoption milestone or a universal speed claim.","lenses":["software_efficiency"],"primary":true,"selection_rationale":"ChaCha is the unauthenticated ARX stream primitive underlying the later IETF AEAD profile; its node prevents software-oriented keystream generation from being mistaken for ChaCha20-Poly1305's authentication contract.","thread":"stream_aead","visibility":"backbone"},"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Ascon permutation-based AEAD","lane_rationale":"The initial Ascon submission specifies the original keyed-duplex AEAD architecture around a 320-bit permutation and domain-separated phases; later normative profiles remain distinct records.","lenses":["lightweight_standardization"],"primary":true,"selection_rationale":"Ascon introduces the compact permutation-based AEAD architecture that precedes NIST's later profile; the node is needed to keep the technical family distinct from the 2025 standardization decision.","thread":"lightweight_permutations","visibility":"backbone"}},"overview_reading_path":[],"problems":[{"id":"confidentiality_to_authentication","label":"Confidentiality → authentication","question":"How did symmetric encryption move from confidentiality-only modes to integrated authenticated encryption?","reading_path":[]},{"id":"nonce_misuse","label":"Nonce misuse","question":"Which designs remain safe when nonce uniqueness fails, and what damage remains unavoidable?","reading_path":[]},{"id":"software_efficiency","label":"Software efficiency","question":"Which primitive and mode choices provide high-throughput authenticated encryption across platforms?","reading_path":["SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER"]},{"id":"lightweight_standardization","label":"Lightweight standardization","question":"Which AEAD architectures remain efficient in constrained devices and become normative standards?","reading_path":["SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD"]}],"relations":[{"change_dimensions":["implementation"],"evidence_locator":"FIPS 197 Introduction and NIST AES selection history","evidence_url":"https://csrc.nist.gov/pubs/fips/197/final","id":"lineage-c312065ed937f415","map_relation":"reference","predecessor":"SYM-RESULT-1977-DES-DES-64-BIT-BLOCK-CIPHER-STANDARD","relation_basis":"model_relation","relation_type":"SUPERSEDES_STANDARD","review_status":"primary_source_checked","statement":"FIPS 197 standardizes AES after the AES competition as the replacement for the aging DES standard, with a 128-bit block and larger keys.","successor":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD"},{"change_dimensions":["mechanism"],"evidence_locator":"SP 800-38A Sections 1, 5, and 6.5","evidence_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","id":"lineage-fc026e852cea86b2","map_relation":"reference","predecessor":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","relation_basis":"technical_dependency","relation_type":"USES_PRIMITIVE","review_status":"primary_source_checked","statement":"SP 800-38A specifies CTR as a confidentiality mode over an approved block cipher such as AES; counter blocks must remain distinct under one key.","successor":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"SP 800-38C Sections 1 and 6","evidence_url":"https://csrc.nist.gov/pubs/sp/800/38/c/upd1/final","id":"lineage-a0046809b117eed4","map_relation":"reference","predecessor":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"CCM combines CTR-mode encryption with CBC-MAC authentication and a formatted associated-data input.","successor":"SYM-RESULT-2004-CCM-CCM-CTR-CBC-MAC-AEAD"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"SP 800-38D Sections 5–7","evidence_url":"https://csrc.nist.gov/pubs/sp/800/38/d/final","id":"lineage-f3cd6bf04bb7fb9b","map_relation":"reference","predecessor":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"GCM uses counter-mode encryption and adds GHASH polynomial authentication to obtain AEAD.","successor":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD"},{"change_dimensions":["mechanism","functionality","security"],"evidence_locator":"RFC 5297 Sections 2.2 and 2.6","evidence_url":"https://www.rfc-editor.org/rfc/rfc5297.html","id":"lineage-2c6cee48dc3ecb42","map_relation":"reference","predecessor":"SYM-RESULT-2001-SP80038A-CTR-CONFIDENTIALITY-MODE","relation_basis":"technical_dependency","relation_type":"COMBINES","review_status":"primary_source_checked","statement":"AES-SIV computes a synthetic IV with S2V and then uses the result as the counter-mode input for encryption.","successor":"SYM-RESULT-2008-SIV-AES-SIV-NONCE-MISUSE-RESISTANT-AEAD"},{"change_dimensions":["mechanism","functionality"],"evidence_locator":"RFC 8439 Sections 2.3–2.8","evidence_url":"https://www.rfc-editor.org/rfc/rfc8439.html","id":"lineage-1827583d97ef39d1","map_relation":"reference","predecessor":"SYM-RESULT-2008-CHACHA-CHACHA-ARX-STREAM-CIPHER","relation_basis":"technical_dependency","relation_type":"COMPOSES","review_status":"primary_source_checked","statement":"RFC 8439 fixes the ChaCha20 profile and composes it with a one-time Poly1305 authenticator to define an AEAD.","successor":"SYM-RESULT-2018-RFC8439-CHACHA20-POLY1305-AEAD"},{"change_dimensions":["mechanism","security"],"evidence_locator":"RFC 8452 Sections 3–6","evidence_url":"https://www.rfc-editor.org/rfc/rfc8452.html","id":"lineage-08c4b0eb2dc9f53f","map_relation":"reference","predecessor":"SYM-RESULT-2007-GCM-GCM-COUNTER-MODE-PLUS-UNIVERSAL-HASH-AEAD","relation_basis":"technical_dependency","relation_type":"HARDENS","review_status":"primary_source_checked","statement":"AES-GCM-SIV changes GCM's nonce-failure profile by deriving per-record keys and a synthetic IV before counter-mode encryption.","successor":"SYM-RESULT-2019-GCMSIV-AES-GCM-SIV-MISUSE-RESISTANT-AEAD"},{"change_dimensions":["implementation"],"evidence_locator":"SP 800-232 Abstract and Sections 3–4","evidence_url":"https://csrc.nist.gov/pubs/sp/800/232/final","id":"lineage-2a2f6a975a480cb0","map_relation":"reference","predecessor":"SYM-RESULT-2014-ASCON-ASCON-PERMUTATION-BASED-LIGHTWEIGHT-AEAD","relation_basis":"technical_dependency","relation_type":"STANDARDIZES","review_status":"primary_source_checked","statement":"SP 800-232 standardizes the selected Ascon family as Ascon-AEAD128 and related hash/XOF algorithms with a fixed NIST profile.","successor":"SYM-RESULT-2025-SP800232-ASCON-AEAD128-NORMATIVE-STANDARD"},{"change_dimensions":["mechanism"],"evidence_locator":"SP 800-38A Sections 1, 5, and 6.2","evidence_url":"https://csrc.nist.gov/pubs/sp/800/38/a/final","id":"lineage-6031a23151d3c27b","map_relation":"reference","predecessor":"SYM-RESULT-2001-AES-AES-128-BIT-BLOCK-CIPHER-STANDARD","relation_basis":"technical_dependency","relation_type":"USES_PRIMITIVE","review_status":"primary_source_checked","statement":"SP 800-38A specifies CBC as a confidentiality mode over an approved block cipher such as AES; it does not add authentication.","successor":"SYM-RESULT-2001-SP80038A-CBC-CONFIDENTIALITY-MODE"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"Standardized block-cipher primitives used by later modes.","id":"block_cipher_standards","label":"Block-cipher standards"},{"color":"#2f718e","description":"Block-cipher modes that provide confidentiality but not integrated authenticity.","id":"confidentiality_modes","label":"Confidentiality modes"},{"color":"#4f7b60","description":"Counter-mode encryption combined with MAC or universal hashing.","id":"composed_aead","label":"Composed AEAD"},{"color":"#73549a","description":"Software-oriented stream ciphers and their authenticated composition.","id":"stream_aead","label":"Stream-cipher AEAD"},{"color":"#b65358","description":"Synthetic-IV designs that bound damage from nonce reuse.","id":"misuse_resistance","label":"Misuse resistance"},{"color":"#9a6c2d","description":"Permutation-based AEAD optimized for constrained environments.","id":"lightweight_permutations","label":"Lightweight permutations"}]},"stats":{"constructions":11,"countsByType":{"assumption":8,"construction":11,"paper":11,"result":12},"entities":42,"lineageRelationships":0,"propertyAssertions":171,"relationships":43,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}