Research shelf / Cryptography / ARIA

Cryptography

ARIA — an AEAD scheme that cannot lose nonce synchronisation

AES-GCM and ChaCha20-Poly1305 both fail badly when a nonce desynchronises after loss of state. ARIA removes the failure mode by never transmitting a nonce at all: it derives one deterministically from the message and the session key, over a three-layer algebraic tower of finite fields.

Reference implementation AGPL-3.0+ / commercial
Evidence level

Code exists and runs. Performance not independently checked.

FolderARIA Encryption Algorithm
FieldCryptography
StatusPrototype. Explicitly not for production use.
What it is

Authenticated encryption that derives the nonce from the message and session key instead of transmitting it, making sender/receiver drift structurally impossible.

ARIA is an authenticated-encryption scheme built to address one specific operational vulnerability in modern AEAD standards: nonce desynchronisation under loss of state. In deployed systems this is not a theoretical concern — a device that reboots, a link that drops, a replica that forks, and the nonce discipline that guarantees security is gone.

Rather than transmit the nonce, ARIA computes it from the message and session key as N(M, sk) = C(M, sk) · β_vec, with a Vandermonde matrix derived from the session key. Recovery from drift is not a recovery procedure; there is nothing to resynchronise.

The construction rests on a three-layer tower: a GF(2256) base using the irreducible polynomial x²⁵⁶ + x¹⁰ + x⁵ + x² + 1, a degree-8 extension L₂ for mid-layer mixing, and a degree-4 extension L₃ providing roughly 8192 bits of diffusion structure.

Do not deploy this. A cryptographic scheme with no external audit, no side-channel analysis and no unforgeability proof is a research object, not a security control. It is published so it can be attacked, which is the only way it ever becomes more than a prototype.
Claims ledger

Every number, and what stands behind it

A claim is only worth the evidence attached to it. Each row below carries its basis: measured on the author’s own hardware, derived from the construction, measured on synthetic data, projected from literature, or simply cited.

Breakdown of this page’s claims by what stands behind each one
scroll to see the whole chart →
Every claim, weighted by its evidence. The table below is the same data row by row.
ClaimFigureBasisContext
Collision-resistance boundAdv_COLL ≤ min(ε_PRF + 7Q²/2²⁵⁷, 2⁻⁸⁶)DerivedTwo bounds converging on one advantage metric
Classical security at Q ≤ 2⁶⁴~2⁻¹²⁶DerivedRealistic query limit substituted into the bound
Classical ISD hardness~2⁸⁶DerivedSyndrome-decoding analysis on a [2048, 256] code
Quantum advantage~2⁴³DerivedMotivates migration to GF(2⁵¹²)
GF(2²⁵⁶) multiplication~46.1 µsMeasuredPure Python reference, author hardware
Encryption throughput155–175 ops/secMeasuredPure Python reference, author hardware
Full AEAD round-trip68–69 ops/secMeasuredPure Python reference, author hardware

Measured — author-run experiment on the stated setup. Synthetic — measured, but on synthetic rather than real data. Derived — follows from the stated construction or proof. Projected — paper-stated projection, not an author-run benchmark. Cited — taken from external literature.

Methods

How it works

  • Three-layer algebraic tower. GF(2²⁵⁶) base, degree-8 extension for mixing, degree-4 extension for diffusion.
  • Deterministic nonce derivation. The nonce is a function of message and session key, so it is never a transmitted, losable value.
  • Vandermonde key schedule. The β vector used in nonce computation is derived from the session key.
  • Syndrome-decoding security analysis. Hardness argued against a [2048, 256] code under information-set decoding.
Stated limitations

What it does not do

Taken from the folder’s own README. Nothing here has been softened.

  • No formal EUF-CMA proof for tag unforgeability.
  • The Meta-DAG entropy source has no formal reduction to a hardness assumption.
  • Post-quantum margin is insufficient without upgrading the field to GF(2⁵¹²).
  • Zero external cryptographic audit.
  • No side-channel analysis and no timing resistance.
Use it

Free under AGPL-3.0+ for almost everyone

Personal use, charities, education and organisations under AUD 50,000 a year pay nothing. A tiered commercial licence covers everyone else.