Operation Count as a Performance Predictor: An Empirical Study of Lightweight AEAD Schemes
DOI:
https://doi.org/10.64552/wipiec.v12i2.138Keywords:
performance estimation, lightweight cryptography, boolean masking, softwareAbstract
This paper presents an analytical model for estimating the performance of cryptographic algorithms based on operation counting at the specification level. Aside from the requirement of having 32-bit operations available on the target, the proposed approach avoids platform-dependent assumptions by deriving a cost metric directly from the number of operations required by an algorithm description. This enables early-stage, target-independent performance comparison. The model is evaluated using the NIST lightweight cryptography competition benchmark results, where it is shown to accurately approximate cycle counts across a diverse set of algorithms. The results indicate that operation counting can provide a consistent relative ordering of computational cost, and even a good order of magnitude approximation, despite its simplicity compared to empirical measurement methods. In addition, the model is applied to algorithms protected against side-channel attacks using first-order Boolean masking schemes implemented with ISW gadgets. While the method has not yet been formally validated for masked implementations, it is used as an exploratory indicator of the additional overhead introduced by the masking countermeasure. Overall, this work suggests that specification-level operation counting can serve as a practical and low-cost tool for early performance estimation and comparative analysis of unprotected, and possibly masked cryptographic implementations.
References
Subhadeep Banik, Avik Chakraborti, Akiko Inoue, Tetsu Iwata, Kazuhiko Minematsu, Mridul Nandi, Thomas Peyrin, Yu Sasaki, Siang Meng Sim, and Yosuke Todo. GIFT-COFB. Cryptology ePrint Archive, Paper 2020/738, 2020.
Zhenzhen Bao, Avik Chakraborti, Nilanjan Datta, Jian Guo, Mridul Nandi, Thomas Peyrin, and Kan Yasuda. Photon-beetle, 2021. Accessed: 2024-12-11.
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschadl, Amir Moradi, L¨ eo Perrin, Aein Rezaei Shahmirzadi, Ale-ksei´ Udovenko, Vesselin Velichkov, and Qingju Wang. Schwaemm and esch: Lightweight authenticated encryption and hashing using the sparkle permutation family, 2021. Accessed: 2024-12-11.
Guido Bertoni, Joan Daemen, Michael Peeters, and Gilles Van Assche.¨ Keccak. In Thomas Johansson and Phong Q. Nguyen, editors, Advances in Cryptology – EUROCRYPT 2013, pages 313–314, Berlin, Heidelberg, 2013. Springer Berlin Heidelberg.
Tim Beyne, Yu Long Chen, Christoph Dobraunig, and Bart Mennink. El-ephant v2, 2021. Accessed: 2024-12-11.
Nathan Binkert, Bradford Beckmann, Gabriel Black, Steven K. Rein-hardt, Ali Saidi, Arkaprava Basu, Joel Hestness, Derek R. Hower, Tushar Krishna, Somayeh Sardashti, Rathijit Sen, Korey Sewell, Muhammad Shoaib, Nilay Vaish, Mark D. Hill, and David A. Wood. The gem5 simu-lator. SIGARCH Comput. Archit. News, 39(2):1–7, August 2011.
Alex Biryukov and Leo Perrin. State of the art in lightweight symmetric´ cryptography. IACR Cryptol. ePrint Arch., 2017:511, 2017.
Jean-Sebastien Coron, Johann Großsch´ adl, and Praveen Vadnala. Se-cure¨ conversion between boolean and arithmetic masking of any order. pages 188–205, 09 2014.
Joan Daemen, Seth Hoffert, Silvia Mella, Michael Peeters, Gilles Van¨ Assche, and Ronny Van Keer. Xoodyak, a lightweight cryptographic scheme, 2021. Accessed: 2024-12-11.
Christoph Dobraunig, Maria Eichlseder, Stefan Mangard, Florian Mendel, Bart Mennink, Robert Primas, and Thomas Unterluggauer. Isapv2.0, 2021. Accessed: 2024-12-11.
Christoph Dobraunig, Maria Eichlseder, Florian Mendel, and Martin Schlaffer. Ascon v1.2: Lightweight authenticated encryption and hash-¨ ing. J. Cryptol., 34(3), July 2021.
Louis Goubin. A sound method for switching between boolean and arith-metic masking. pages 3–15, 05 2001.
Chun Guo, Tetsu Iwata, Mustafa Khairallah nad Kazuhiko Minematsu, and Thomas Peyrin. Romulus-v1.3, 2021. Accessed: 2024-12-11.
Martin Hell, Thomas Johansson, Alexander Maximov, Willi Meier, Jona-than Sonnerup, and Hirotaka Yoshida.¨ Grain-128aeadv2, 2021. Ac-cessed: 2024-12-11.
Yuval Ishai, Amit Sahai, and David Wagner. Private circuits: Securing hardware against probing attacks. In Dan Boneh, editor, Advances in Cryp-tology - CRYPTO 2003, pages 463–481, Berlin, Heidelberg, 2003.
Springer Berlin Heidelberg.
M. G. Kendall. Rank correlation methods. 1949.
Chris Lattner and Vikram Adve. LLVM: A Compilation Framework for Lifelong Program Analysis & Transformation. In Proceedings of the
International Symposium on Code Generation and Optimization (CGO’04), Palo Alto, California, Mar 2004.
Kerry McKay, Lawrence Bassham, Meltem Sonmez Turan, and Nicky
Mouha. Report on lightweight cryptography, 2017-03-28 00:03:00 2017.
Karl Pearson and Francis Galton. Vii. note on regression and inheritance in the case of two parents. Proceedings of the Royal Society of London, 58(347-352):240–242, 1895.
Reinhard Wilhelm, Jakob Engblom, Andreas Ermedahl, Niklas Holsti, Stephan Thesing, David Whalley, Guillem Bernat, Christian Ferdinand,
Reinhold Heckmann, Tulika Mitra, Frank Mueller, Isabelle Puaut, Peter Puschner, Jan Staschulat, and Per Stenstrom. The worst-case execution-¨ time problem—overview of methods and survey of tools. ACM Trans. Embed. Comput. Syst., 7(3), May 2008.
Hongjun Wu and Tao Huang. Tinyjambu: A family of lightweight authen-ticated encryption algorithms(version 2), 2021. Accessed: 202412-11.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Raphaël Wintersdorff, Renaud Pacalet, Laurent Sauvage

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
License Terms:
Except where otherwise noted, content on this website is lincesed under a Creative Commons Attribution Non-Commercial License (CC BY NC)
![]()
Use, distribution and reproduction in any medium, provided the original work is properly cited and is not used for commercial purposes, is permitted.
Copyright to any article published by WiPiEC retained by the author(s). Authors grant WiPiEC Journal a license to publish the article and identify itself as the original publisher. Authors also grant any third party the right to use the article freely as long as it is not used for commercial purposes and its original authors, citation details, and publisher are identified, in accordance with CC BY NC license. Fore more information on license terms, click here.