Design rationale and designers’ results on Ascon’s security:

Ascon permutation

Cube-like key-recovery attack on 7-round Ascon in 2103.9 time:

Cube-like attacks in a nonce-misuse setting:

Security of Ascon against state-recovery attacks:

Differential distinguishers based on undisturbed bits for 5 rounds with 2109 data:

Security of Ascon’s S-box against division property attacks:

Linear characteristic for 5 rounds with 67 active S-boxes, bias 2−94:

Integral distinguishers for 5 to 11 rounds, e.g., 265 texts for 7 rounds:

Linear, differential, cube-like attacks (key recovery: 6 rounds, permutation distinguisher):

Ascon mode

Ascon’s mode supports secure implementations on limited-memory devices:

Suggestions to absorb authenticated data more efficiently:

Security proof for Ascon’s sponge mode even for higher rates:

Ascon implementation

