Lightweight Cryptography Standardization Process: NIST Selects Ascon
csrc.nist.gov
csrc.nist.gov
NIST has been testing the algorithms on ATmega328P in software, with specific comparisons to AES-GCM, where Ascon was twice as fast[0]. They also study hardware designs for various fabs; there was a study also giving significantly better results there[1].
> supports 256-bit keys (which are actually secure against quantum search)
(Small note here: this topic is a bit more complex than this, since Grover’s algorithm does not have a constant gate factor with respect to the number of key bits. 128-bit keys already require a number of gates that is unrealistic for a quantum computer to have, similar to expecting a classical computer to have over a quettabyte of RAM.)
[0]: https://csrc.nist.gov/csrc/media/Presentations/2022/update-o...
[1]: https://cryptography.gmu.edu/athena/LWC/SCA_Evaluation_and_B...
Ascon, depending on the implementation, requires far less logic gates than AES to implement in hardware and requires less power, which would be an eventual cost savings.
I think most importantly though is that by not going with an ARX-based design (Addition, Rotation, XOR), it's much easier for cryptographers to perform cryptanalysis, which is what the Keccak team attributes to why it took so long to find vulnerabilities with algorithms like MD5.
ChaCha20 is an ARX construction. Ascon is Sponge construction (more akin to Keccak and all its versions and friends).