Research shelf / Cryptography / ARIA
Written Updated
ARIA — an AEAD scheme that cannot lose nonce synchronisation
AES-GCM and ChaCha20-Poly1305 both fail badly when a nonce desynchronises after loss of state. ARIA removes the failure mode by never transmitting a nonce at all: it derives one deterministically from the message and the session key, over a three-layer algebraic tower of finite fields.
Code exists and runs. Performance not independently checked.
Authenticated encryption that derives the nonce from the message and session key instead of transmitting it, making sender/receiver drift structurally impossible.
ARIA is an authenticated-encryption scheme built to address one specific operational vulnerability in modern AEAD standards: nonce desynchronisation under loss of state. In deployed systems this is not a theoretical concern — a device that reboots, a link that drops, a replica that forks, and the nonce discipline that guarantees security is gone.
Rather than transmit the nonce, ARIA computes it from the message and session key as N(M, sk) = C(M, sk) · β_vec, with a Vandermonde matrix derived from the session key. Recovery from drift is not a recovery procedure; there is nothing to resynchronise.
The construction rests on a three-layer tower: a GF(2256) base using the irreducible polynomial x²⁵⁶ + x¹⁰ + x⁵ + x² + 1, a degree-8 extension L₂ for mid-layer mixing, and a degree-4 extension L₃ providing roughly 8192 bits of diffusion structure.
Every number, and what stands behind it
A claim is only worth the evidence attached to it. Each row below carries its basis: measured on the author’s own hardware, derived from the construction, measured on synthetic data, projected from literature, or simply cited.
| Claim | Figure | Basis | Context |
|---|---|---|---|
| Collision-resistance bound | Adv_COLL ≤ min(ε_PRF + 7Q²/2²⁵⁷, 2⁻⁸⁶) | Derived | Two bounds converging on one advantage metric |
| Classical security at Q ≤ 2⁶⁴ | ~2⁻¹²⁶ | Derived | Realistic query limit substituted into the bound |
| Classical ISD hardness | ~2⁸⁶ | Derived | Syndrome-decoding analysis on a [2048, 256] code |
| Quantum advantage | ~2⁴³ | Derived | Motivates migration to GF(2⁵¹²) |
| GF(2²⁵⁶) multiplication | ~46.1 µs | Measured | Pure Python reference, author hardware |
| Encryption throughput | 155–175 ops/sec | Measured | Pure Python reference, author hardware |
| Full AEAD round-trip | 68–69 ops/sec | Measured | Pure Python reference, author hardware |
Measured — author-run experiment on the stated setup. Synthetic — measured, but on synthetic rather than real data. Derived — follows from the stated construction or proof. Projected — paper-stated projection, not an author-run benchmark. Cited — taken from external literature.
How it works
- Three-layer algebraic tower. GF(2²⁵⁶) base, degree-8 extension for mixing, degree-4 extension for diffusion.
- Deterministic nonce derivation. The nonce is a function of message and session key, so it is never a transmitted, losable value.
- Vandermonde key schedule. The β vector used in nonce computation is derived from the session key.
- Syndrome-decoding security analysis. Hardness argued against a [2048, 256] code under information-set decoding.
What it does not do
Taken from the folder’s own README. Nothing here has been softened.
- No formal EUF-CMA proof for tag unforgeability.
- The Meta-DAG entropy source has no formal reduction to a hardness assumption.
- Post-quantum margin is insufficient without upgrading the field to GF(2⁵¹²).
- Zero external cryptographic audit.
- No side-channel analysis and no timing resistance.
Free under AGPL-3.0+ for almost everyone
Personal use, charities, education and organisations under AUD 50,000 a year pay nothing. A tiered commercial licence covers everyone else.