Skip to main navigation Skip to search Skip to main content

Differential fault attacks on the lightweight authenticated encryption algorithm CLX-128

Research output: Contribution to journalArticleResearchpeer-review

Abstract

We investigate a technique that needs to apply multiple random faults to the same target location and compare the impact of these faults on the fault-free and faulty output to recover specific secret variable. A mix of random effective and ineffective faults is considered in our analysis. In this paper, we apply these random faults to CLX-128, a first round candidate in the National Institute of Standards and Technology lightweight cryptography project, to recover the secret key of the cipher. We also investigate the bit-flipping fault applications to CLX-128. We show that both of these fault models can be applied to CLX-128 to recover its internal state. The application of the random fault model to CLX-128 requires 134 faulty queries to recover certain state bits, whereas the bit-flipping fault model requires 54 faulty queries to recover certain state bits. The remaining state bits are recovered by solving a system of linear equations. The complexity of the attacks is 2 36 . In our applications, the random fault model requires comparatively large number of faults, but the underlying assumptions of the random fault model are less strict and hence more practical, as the adversary does not need to have a prior knowledge on the impact of the fault.

Original languageEnglish
Pages (from-to)265-281
Number of pages17
JournalJournal of Cryptographic Engineering
Volume13
Issue number3
DOIs
Publication statusPublished - Sept 2023

Keywords

  • CLX-128
  • Fault attack
  • Key recovery
  • NIST LWC project
  • Random fault
  • State recovery

Cite this