The DRACO V1 Stream Cipher
Subhadeep Banik, Matthias Hamann, Matthias Krause, Alexander Moch, Francesco Regazzoni, Linda Scheu-Hachtel · IACR Transactions on Symmetric Cryptology · 2026
Time-memory-data tradeoff attacks, as described by Babbage (1995), Golić (1997), and Biryukov and Shamir (2001), require the internal state of a stream cipher to be at least twice the desired security level n, or equivalently twice the key length. In conventional stream ciphers, the secret key and the IV are loaded into the cipher prior to keystream generation, after which the cipher operates exclusively on a volatile internal state stored in the hardware module. So-called small-state stream ciphers reduce the size of this volatile state below 2n by reusing, during keystream generation, the wires employed for loading the secret key and IV. In this setting, the key and IV are non-volatile and not part of the hardware module's modifiable state. Although the entire state still meets the 2n requirement, the hardware footprint can be significantly reduced. DRACO is a small-state stream cipher published in IACR ToSC 2022 and presented at FSE 2023. It features a 128-bit volatile state and a 128-bit non-volatile state, the latter consisting of a 96-bit public initial value and a 32-bit key prefix. Reusing the secret key and IV during keystream generation requires the stream cipher to employ a key-IV schedule; a task that historically has not been a concern in stream cipher design. At the same conference, an attack was presented that exploits a weakness in DRACO's key-IV schedule, reducing its security to approximately 108 bits. Fixing this issue turns out to be highly nontrivial. In this update, we introduce DRACO V1 an improved version of DRACO that is resistant to the style of attack presented in the aforementioned FSE 2023 paper. The new design employs an IV extension technique that is hardware-efficient and requires only a minimal increase in gate count. We refined the design through multiple iterations, carefully analyzing its security at each stage. Our evaluation includes an extensive analysis of all known attacks against such structures. Additionally, we synthesized the circuit using two standard cell libraries and found that DRACO V1 is approximately 10-15% smaller than all other stream ciphers offering 128-bit security.