Crypto etymology
What's the origins of names like Ascon, Keccak, Kyber, and Rijndael?
There are only two hard things in Computer Science: cache invalidation and naming things.
This is a quote attributed to Phil Karlton, a famous Netscape (now, that’s a trip to the past!) developer.
Naming a cipher is one of the funniest parts of the design process. You want a name that’s memorable, easy to pronounce, and with no embarrassing meaning in any language or slang. It’s even better if the name is somehow connected to cipher, its structure or its ancestry. So let’s look at some remarkable crypto primitives names, in alphabetical order.
Ascon
Ascon is a family of lightweight authenticated ciphers and hashes selected by NIST for resource-constrained devices, specified in SP 800-232.
Ascon is a sponge function, and the asconoid is the simplest type of marine sponge:
BLAKE (1, 2, 3)
I don’t include it because it’s the most interesting, but because I chose it myself. It’s a reference to William Blake and to a lake nearby. Someone asked recently, and here’s my response, typos included:
ChaCha20 & Salsa20
The ChaCha20 of the ChaCha20-Poly1303 authenticated cipher (as used in TLS 1.3 and SSH) is a variant of Salsa20:
The obvious connection is that like salsa, cha-cha is a Latin dance.
Salsa20 can be seen as related to salsa in the following way (this is purely my own speculation and imagination): the internal state of Salsa20 is a 4×4 array (like salsa has a 4/4 time signature), modified by repeating two different steps (columnround and rowround) each consisting of 4 applications of the 4-word sequence rowround. The repeated modification of diagonal sequences can even remind of salsa’s diagonal step.
Finally, Salsa20 as initially called Snuffle 2005, after Bernstein’s Snuffle from the 1990s’ crypto wars.
Keccak
Pronunced “ketchak” and not “kekak”, the name comes from the Balinese dance Kecak, as for example referenced in the designers’ NIST presentation:
Chaskey
Chaskey is a fast message authentication code (MAC) optimized for 32-bit systems, and inspired by SipHash. As the authors explain:
The name Chaskey is derived from Chasqui, also written as Chaski. Chasquis were fast runners that delivered messages in the Inca empire. They were of short stature, and could cover large distances through mountainous areas with little nutrition available to them
This is actually super interesting:
The chasqui system could deliver a message or a gift along a distance of up to 300 kilometres (190 mi) per day.
Kyber (ML-KEM)
In Star Wars lore,
A kyber crystal, simply known as a kyber and described as a lightsaber crystal or the living crystal, was a rare, Force-attuned crystal that grew naturally and was found on various planets across the galaxy.
With the signature scheme Dilithium, the KEM Kyber is part of the CRYSTALS (Cryptographic Suite for Algebraic Lattices) initiative. Kyber is an evolution of NewHope, whose name is an obvious reference to SW Episode IV.
PRESENT
It may be the least SEO-friendly name, but PRESENT is an underappreciated block cipher; it’s a lightweight block cipher that is simple to analyze, understand, and implement. PRESENT is an anagram of SERPENT, the AES candidate it’s inspired from. PRESENT is now an ISO/IEC standard (29167-11:2025).
Rijndael (a.k.a. AES)
This may be the best known, at least among cryptographers. But perhaps not everybody knows that what’s now called AES (Advanced Encryption Standard) is based on the Rijndael submission to the AES. The name is a portmanteau of the names of the designers Joan Daemen and Vincent Rijmen.
After Rijndael was chosen, its internal components were also renamed:
SPHINCS+ (SLH-DSA)
SPHINCS+ is a variant of SPHINCS: Stateless Practical Hash-based Incredibly Nice Collision-resilient Signatures, as documented in presentations of SPHINCS. Until this post, I didn’t know (or forgot) this, and thought it was an actual, boring, accurate description of what SPHINCS does.
Featured image: Peter Bruegel, The Tower of Babel (detail)




