Search arXiv⌕ Search

arXiv subjects

Peipei Xie

Publications and source records attributed to Peipei Xie.

2 recordsLinked to original sources

Differential Fault Analysis of Lilliput under Random-Location Nibble Faults

Differential fault analysis (DFA) is an important technique for evaluating the implementation-level security of block ciphers. Many DFA attacks assume that the adversary can inject faults into a selected internal word, nibble, or branch. Such fixed-location assumptions are convenient for deriving key-recovery equations, but they may overestimate the adversary's spatial control and may obscure the branch-dependent leakage behavior of multi-branch structures. In this paper, we study the lightweight block cipher Lilliput under a fixed-timing full-branch random-location nibble fault model. The attacker is assumed to induce a nonzero nibble fault in round 27, while the affected branch is randomly distributed over all sixteen state branches and is unknown to the attacker. The main challenge is to convert faulty ciphertexts with unknown injection locations into usable key-recovery constraints. We analyze the fault propagation induced by the EGFN structure of Lilliput and derive ciphertext-difference conditions for identifying the injected branch. The proposed branch-identification approach has a DDT-based combinatorial estimate of at least 99.9909% and achieves 99.9983% accuracy in 2^{20} random fault simulations. Once the fault branch is determined, we classify the corresponding propagation patterns according to whether the injected fault value and the intermediate S-box output difference can be uniquely determined. For each case, we derive DDT-based constraints on the last-round and penultimate-round subkeys and combine multiple faulty ciphertexts by candidate-set intersection. Simulation experiments over 2^{15} trials show that the attack reaches key-recovery success rates of over 90%, 95%, and 99% with 32, 36, and 46 faulty ciphertexts, respectively. These results show that Lilliput exhibits exploitable branch-dependent leakage even when the attacker cannot control the exact fault location.

cs.CR↗

Cryptanalysis of Gleeok-128

Gleeok is a family of low latency keyed pseudorandom functions (PRFs) consisting of three parallel SPN based permutations whose outputs are XORed to form the final value. Both Gleeok-128 and Gleeok-256 use a 256 bit key, with block sizes of 128 and 256 bits, respectively. Owing to its multi branch structure, evaluating security margins and mounting effective key recovery attacks present nontrivial challenges. This paper provides the first comprehensive third party cryptanalysis of Gleeok-128. We introduce a two stage MILP based framework for constructing branch wise and full cipher differential linear (DL) distinguishers, together with an integral based key recovery framework tailored to multi branch designs. Our DL analysis yields 7, 7, 8, and 4 round distinguishers for Branch 1, Branch 2, Branch 3, and Gleeok-128, respectively, with squared correlations approximately 2 to the power minus 88.12, 2 to the power minus 88.12, 2 to the power minus 38.73, and 2 to the power minus 49.04, outperforming those in the design document except for the full PRF case. By tightening algebraic degree bounds, we further derive 9, 9, and 7 round integral distinguishers for the three branches and a 7 round distinguisher for the full PRF, extending the designers results by 3, 3, and 2 rounds and by 2 rounds, respectively. These integral properties enable 7 round and 8 round key recovery attacks in the non full codebook and full codebook settings. In addition, we identify a flaw in the original linear security evaluation of Branch 3, showing that it can be distinguished over all 12 rounds with data complexity about 2 to the power 48. We also propose optimized linear layer parameters that significantly improve linear resistance without sacrificing diffusion. Our results advance the understanding of Gleeok-128 and provide general methods for analyzing multi branch symmetric designs.

cs.CR↗