Decomposition of higher-order nonlinear S-boxes in lightweight block ciphers for algebraic fault analysis

preprint OA: closed
View at publisher

Abstract

Abstract Nowadays, with the development of Internet of Things and information security technologies, lightweight block ciphers are gradually being widely used. As a sidechannel attack method, algebraic fault analysis has received attention from experts and scholars since its introduction. The only nonlinear operation in lightweight block ciphers is S box substitution, and the performance index of S box directly determines the security strength of the cipher.In order to further improve the efficiency of algebraic fault analysis, this paper proposes a method to rewrite the algebraic equations of S box substitution by decomposing the original cubic S boxes into two quadratic S boxes. The results show that this method is significantly effective compared to the original method in GIFT 64 and SKINNY 64, especially in SKINNY 64 block cipher, where the average solving time is reduced by several hundred times in the best case with the same samples. At the same time, the need for the number of faults is reduced, and at least 2 faulty ciphertexts can be used to recover the master key. In addition, the PRESENT 64 block cipher is also studied in this paper, and the results show that the method can also improve the efficiency significantly when the number of fault injection rounds is deep.

My notes (saved in your browser only)

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.

Source provenance

europepmc
last seen: 2026-05-19T01:45:01.086888+00:00