{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T00:36:03Z","timestamp":1785285363511,"version":"3.55.0"},"reference-count":38,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2018,3,8]],"date-time":"2018-03-08T00:00:00Z","timestamp":1520467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>In Fast Software Encryption (FSE) 2015, while presenting a new idea (i.e., the design of stream ciphers with the small internal state by using a secret key, not only in the initialization but also in the keystream generation), Sprout was proposed. Sprout was insecure and an improved version of Sprout was presented in FSE 2017. We introduced Fruit stream cipher informally in 2016 on the web page of IACR (eprint) and few cryptanalysis were published on it. Fortunately, the main structure of Fruit was resistant. Now, Fruit-80 is presented as a final version which is easier to implement and is secure. The size of LFSR and NFSR in Fruit-80 is only 80 bits (for 80-bit security level), while for resistance to the classical time-memory-data tradeoff (TMDTO) attacks, the internal state size should be at least twice that of the security level. To satisfy this rule and to design a concrete cipher, we used some new design ideas. It seems that the bottleneck of designing an ultra-lightweight stream cipher is TMDTO distinguishing attacks. A countermeasure was suggested, and another countermeasure is proposed here. Fruit-80 is better than other small-state stream ciphers in terms of the initialization speed and area size in hardware. It is possible to redesign many of the stream ciphers and achieve significantly smaller area size by using the new idea.<\/jats:p>","DOI":"10.3390\/e20030180","type":"journal-article","created":{"date-parts":[[2018,3,8]],"date-time":"2018-03-08T12:07:33Z","timestamp":1520510853000},"page":"180","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["Fruit-80: A Secure Ultra-Lightweight Stream Cipher for Constrained Environments"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9190-9698","authenticated-orcid":false,"given":"Vahid","family":"Amin Ghafari","sequence":"first","affiliation":[{"name":"Key Laboratory of Electromagnetic Space Information, Chinese Academy of Sciences, School of Information Science and Technology, University of Science and Technology of China, Hefei 230026, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8903-8413","authenticated-orcid":false,"given":"Honggang","family":"Hu","sequence":"additional","affiliation":[{"name":"Key Laboratory of Electromagnetic Space Information, Chinese Academy of Sciences, School of Information Science and Technology, University of Science and Technology of China, Hefei 230026, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2018,3,8]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1007\/11836810_13","article-title":"Trivium: A Stream Cipher Construction Inspired by Block Cipher Design Principles","volume":"4176","year":"2006","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_2","unstructured":"Babbage, S., and Dodd, M. (2018, March 06). The Stream Cipher MICKEY 2.0. Available online: http:\/\/www.ecrypt.eu.org\/stream\/p3ciphers\/mickey\/mickey_p3.pdf."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1504\/IJWMC.2007.013798","article-title":"Grain: A stream cipher for constrained environments","volume":"2","author":"Hell","year":"2007","journal-title":"Int. J. Wirel. Mob. Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1007\/978-3-540-70500-0_24","article-title":"Related-Key Chosen IV Attacks on Grain-v1 and Grain-128","volume":"5107","author":"Lee","year":"2008","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Hell, M., Johansson, T., Maximov, A., and Meier, W. (2006, January 9\u201314). A stream cipher proposal: Grain-128. Proceedings of the IEEE International Symposium on Information Theory (ISIT 2006), Seattle, WA, USA.","DOI":"10.1109\/ISIT.2006.261549"},{"key":"ref_6","first-page":"218","article-title":"Efficient FPGA Implementations of High-Dimensional Cube Testers on the Stream Cipher Grain-128","volume":"2009","author":"Aumasson","year":"2009","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1007\/978-3-642-25385-0_18","article-title":"An Experimentally Verified Attack on Full Grain-128 Using Dedicated Reconfigurable Hardware","volume":"7073","author":"Dinur","year":"2011","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1007\/978-3-642-21702-9_10","article-title":"Breaking Grain-128 with Dynamic Cube Attacks","volume":"6733","author":"Dinur","year":"2011","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1007\/978-3-642-17373-8_8","article-title":"Conditional Differential Cryptanalysis of NLFSR-Based Cryptosystems","volume":"6477","author":"Knellwolf","year":"2010","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"205","DOI":"10.1007\/s10998-012-4631-8","article-title":"Generic cryptographic weakness of k-normal Boolean functions in certain stream ciphers and cryptanalysis of grain-128","volume":"65","author":"Mihaljevic","year":"2012","journal-title":"Period. Math. Hung."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"210","DOI":"10.1007\/978-3-642-17401-8_16","article-title":"Greedy Distinguishers and Nonrandomness Detectors","volume":"6498","author":"Stankovski","year":"2010","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1504\/IJWMC.2011.044106","article-title":"Grain-128a: A new version of Grain-128 with optional authentication","volume":"5","author":"Hell","year":"2011","journal-title":"Int. J. Wirel. Mob. Comput."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1007\/978-3-642-34416-9_8","article-title":"A Differential Fault Attack on Grain-128a Using MACs","volume":"7644","author":"Banik","year":"2012","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"803","DOI":"10.1109\/TIFS.2013.2256419","article-title":"Related Key Chosen IV Attack on Grain-128a Stream Cipher","volume":"8","author":"Ding","year":"2013","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"451","DOI":"10.1007\/978-3-662-48116-5_22","article-title":"On Lightweight Stream Ciphers with Shorter Internal States","volume":"9054","author":"Armknecht","year":"2015","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1007\/978-3-319-26617-6_7","article-title":"Some Results on Sprout","volume":"9462","author":"Banik","year":"2015","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1007\/978-3-319-31301-6_4","article-title":"Practical Cryptanalysis of Full Sprout with TMD Tradeoff Attacks","volume":"9566","author":"Esgin","year":"2015","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_18","first-page":"231","article-title":"A Related-Key Chosen-IV Distinguishing Attack on Full Sprout Stream Cipher","volume":"2015","author":"Hao","year":"2015","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"663","DOI":"10.1007\/978-3-662-47989-6_32","article-title":"Cryptanalysis of Full Sprout","volume":"9215","author":"Lallemand","year":"2015","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_20","first-page":"236","article-title":"Key Recovery from State Information of Sprout: Application to Cryptanalysis and Fault Attack","volume":"2015","author":"Maitra","year":"2015","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"561","DOI":"10.1007\/978-3-662-48800-3_23","article-title":"Another Tradeoff Attack on Sprout-Like Stream Ciphers","volume":"9453","author":"Zhang","year":"2015","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_22","first-page":"87","article-title":"Cryptanalysis of full round Fruit","volume":"2017","author":"Dey","year":"2017","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_23","unstructured":"Ghafari, V.A., Hu, H., and Xie, C. (2018, March 06). Fruit: Ultra-Lightweight Stream Cipher with Shorter Internal State. Available online: https:\/\/eprint.iacr.org\/2016\/355.pdf."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Hamann, M., Krause, M., Meier, W., and Zhang, B. (2017). Design and analysis of small-state grain-like stream ciphers. Cryptogr. Commun.","DOI":"10.1007\/s12095-017-0261-6"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"58","DOI":"10.46586\/tosc.v2017.i4.58-81","article-title":"Fast Correlation Attacks on Grain-like Small State Stream Ciphers","volume":"2017","author":"Zhang","year":"2017","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"52","DOI":"10.46586\/tosc.v2016.i2.52-79","article-title":"On Ciphers that Continuously Access the Non-Volatile Key","volume":"2016","author":"Mikhalev","year":"2017","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"45","DOI":"10.46586\/tosc.v2017.i1.45-79","article-title":"LIZARD\u2014A lightweight stream cipher for power-constrained devices","volume":"2017","author":"Hamann","year":"2017","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Sohraby, K., Minoli, D., and Znati, T. (2007). Wireless Sensor Networks: Technology, Protocols, and Applications, John Wiley & Sons.","DOI":"10.1002\/047011276X"},{"key":"ref_29","first-page":"109","article-title":"Cryptanalysis of Stream Cipher Grain Family","volume":"2009","author":"Zhang","year":"2009","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1317","DOI":"10.1142\/S0129054111008738","article-title":"Periods on Two Kinds of nonlinear Feedback Shift Registers with Time Varying Feedback Functions","volume":"22","author":"Hu","year":"2011","journal-title":"Int. J. Found. Comput. Sci."},{"key":"ref_31","first-page":"1","article-title":"Real Time Cryptanalysis of A5\/1 on a PC","volume":"1978","author":"Biryukov","year":"2000","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Maximov, A. (2006, January 21\u201324). Cryptanalysis of the \u201cGrain\u201d family of stream ciphers. Proceedings of the 2006 ACM Symposium on Information, Computer and Communications Security, Taipei, Taiwan.","DOI":"10.1145\/1128817.1128859"},{"key":"ref_33","first-page":"207","article-title":"Fault analysis and weak key-IV attack on Sprout","volume":"2016","author":"Roy","year":"2016","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"122","DOI":"10.1007\/978-3-642-33027-8_8","article-title":"A Differential Fault Attack on the Grain Family of Stream Ciphers","volume":"7428","author":"Banik","year":"2012","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Berzati, A., Canovas, C., Castagnos, G., Debraize, B., Goubin, L., Gouget, A., Paillier, P., and Salgado, S. (2009, January 27). Fault analysis of GRAIN-128. Proceedings of the IEEE International Workshop on Hardware-Oriented Security and Trust, Francisco, CA, USA.","DOI":"10.1109\/HST.2009.5225030"},{"key":"ref_36","unstructured":"Good, T., and Benaissa, M. (2008, January 13\u201314). Hardware performance of eStream phase-III stream cipher candidates. Proceedings of the Workshop on the State of the Art of Stream Ciphers (SACS 2008), Lausanne, Switzerland."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"e4","DOI":"10.4108\/sesa.2.3.e4","article-title":"WG-8: A Lightweight Stream Cipher for Resource-Constrained Smart Devices","volume":"2","author":"Fan","year":"2015","journal-title":"ICST Trans. Secur. Saf."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1007\/3-540-69053-0_17","article-title":"Cryptanalysis of Alleged A5 Stream Cipher","volume":"1233","author":"Golic","year":"1997","journal-title":"Lect. Notes Comput. Sci."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/20\/3\/180\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T14:58:00Z","timestamp":1760194680000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/20\/3\/180"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,3,8]]},"references-count":38,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2018,3]]}},"alternative-id":["e20030180"],"URL":"https:\/\/doi.org\/10.3390\/e20030180","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,3,8]]}}}