Archive/Dipper: A Lightweight Hybrid SPN–ARX Block Cipher
Dipper: A Lightweight Hybrid SPN–ARX Block Cipher
Ali Huseynli, Yadigar Imamverdiyev, Jalal Alizadeh
21. Juli 2026
en

Abstract

We present Dipper, a lightweight 64-bit block cipher with 96-bit and 128-bit key variants, built on a 28-round hybrid SPN–ARX structure. Each round applies a full-state key addition, sixteen parallel 4-bit GIFT S-boxes, four word-wise rotations, two 16-bit modular additions over half of the state, and the GIFT-64 bit permutation, combining the compact substitution layer of GIFT-style designs with the diffusion efficiency of ARX operations. We evaluate Dipper from both hardware and cryptanalytic perspectives under a single, fully open-source methodology. Round-based Verilog implementations were synthesized alongside PRESENT, GIFT, and SIMON variants using an identical Yosys + ABC + Nangate45 flow. Under this flow, Dipper-64/96 and Dipper-64/128 require 2498 and 2824 gate equivalents (GE), respectively, both falling between GIFT-64-128 (2191 GE) and PRESENT-128 (2963 GE); notably, Dipper-64/128 is more compact than PRESENT-128 at the same key size, despite incorporating an additional ARX diffusion layer. A broader comparison re-implements eleven established lightweight ciphers under the same flow, and post-place-and-route FPGA results on Lattice ECP5, measured software timings, and Cortex-M memory footprints support deployment across RFID, sensor-node, and edge-gateway scenarios. For differential resistance, we develop a mixed-integer linear programming (MILP) model that couples the exact GIFT differential distribution table with a Lipmaa–Moriai encoding of modular addition. Predicted and empirical differential probabilities agree tightly for reduced-round variants, while five-round trails reveal differential clustering. The security evaluation further includes proven-optimal linear trail bounds up to ten rounds, an exhaustive impossible-differential search bounding the longest distinguisher at five rounds, and experimental integral distinguishers of at most five rounds, leaving the 28-round cipher a margin close to 3× against the longest identified distinguisher. All RTL, synthesis scripts, reference implementations, and MILP models are released for full reproducibility.

IPC Classification

G06

Keywords

dipperlightweighthybridblockciphercryptographypresent64-bit96-bit128-bitvariantsbuilt28-roundstructureeachroundappliesfull-stateadditionsixteenparallel4-bitgifts-boxes
Diese Veröffentlichung zitieren

€ 4.00