Assessing Gaston: Side-channel Security and Hardware Cost Comparison with Ascon-p
Parisa Amiri Eliasi, Silvia Mella, Lejla Batina · 2025
At Crypto 2023, El hirch et al. introduced the cryptographic permutation GASTON. They showed that by using the same number of bitwise operations of ASCON-p - the permutation underlying the new NIST standard ASCON for lightweight authenticated encryption - it is possible to build a permutation that has better resistance against differential and linear cryptanalysis. This makes GASTON an interesting alternative in cryptographic applications. In this paper, we compare GASTON and ASCON-p in terms of resource usage on FPGA and ASIC. Our results show that, despite their similar theoretical costs in bitwise operations, GASTON requires more resources on certain platforms. Additionally, we evaluate the side-channel resistance of the Ascon mode when instantiated with GASTON instead of AScON-p. To this end, we perform correlation power analysis and template attacks using a hardware implementation running on an FPGA platform. By comparing our attack results with an earlier study on AscoN performing correlation power analysis, we observe that the mode instantiated with GASTON achieves a lower success rate for both attacks. This suggests that using GASTON as the underlying permutation improves resistance to this class of attacks.