{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T09:08:47Z","timestamp":1749632927960},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,12,7]],"date-time":"2023-12-07T00:00:00Z","timestamp":1701907200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,12,7]],"date-time":"2023-12-07T00:00:00Z","timestamp":1701907200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["12371525"],"award-info":[{"award-number":["12371525"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Lightweight block ciphers are the essential encryption algorithm for devices with limited resources. Its goal is to ensure the security of data transmission through resource-constrained devices. Impossible differential cryptanalysis is one of the most effective cryptanalysis on block ciphers, and assessing the ability of resisting this attack is a basic design criterion. Shadow is a lightweight block cipher proposed by Guo et al. (IEEE Internet Things J 8(16):13014\u201313023, 2021). It utilizes a combination of ARX operations and generalized Feistel structure to overcome the weakness of the traditional Feistel structure that only diffuses half in one round. In this paper, we focus on the differential property of Shadow and its security against impossible differential cryptanalysis. First, we use the SAT method to automatically search for a full-round impossible differential distinguisher of Shadow-32. Then, based on the experimental results, we prove that Shadow has a differential property with probability 1 based on the propagation of the state. Further, we can obtain an impossible differential distinguisher for an arbitrary number of rounds of Shadow. Finally, we perform a full key recovery attack on the full-round Shadow-32 and Shadow-64. Both experimentally and theoretically, our results indicate that Shadow is critically flawed, and regardless of the security strength of the internal components and the number of rounds applied, the overall cipher remains vulnerable to impossible differential cryptanalysis.<\/jats:p>","DOI":"10.1186\/s42400-023-00184-7","type":"journal-article","created":{"date-parts":[[2023,12,7]],"date-time":"2023-12-07T02:02:05Z","timestamp":1701914525000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Full-round impossible differential attack on shadow block cipher"],"prefix":"10.1186","volume":"6","author":[{"given":"Yuting","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongqiang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huiqin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingsheng","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,12,7]]},"reference":[{"key":"184_CR1","doi-asserted-by":"crossref","unstructured":"Abdelkhalek A, Sasaki Y, Todo Y, Tolba M, Youssef AM (2017) MILP modeling for (large) s-boxes to optimize probability of differential characteristics. IACR Trans Symmetr Cryptol 99\u2013129","DOI":"10.46586\/tosc.v2017.i4.99-129"},{"key":"184_CR2","doi-asserted-by":"crossref","unstructured":"Banik S, Bogdanov A, Isobe T, Shibutani K, Hiwatari H, Akishita T, Regazzoni F (2015) Midori: a block cipher for low energy. In: Proceedings of the advances in cryptology\u2014ASIACRYPT 2015: 21st international conference on the theory and application of cryptology and information security, Auckland, New Zealand, November 29\u2013December 3, 2015, Part II. Springer, vol 21, pp 411\u2013436","DOI":"10.1007\/978-3-662-48800-3_17"},{"key":"184_CR3","doi-asserted-by":"crossref","unstructured":"Beaulieu R, Shors D, Smith J, Treatman-Clark S, Weeks B, Wingers L (2015) The SIMON and SPECK lightweight block ciphers. In: Proceedings of the 52nd annual design automation conference, pp 1\u20136","DOI":"10.1145\/2744769.2747946"},{"key":"184_CR4","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00630563","volume":"4","author":"E Biham","year":"1991","unstructured":"Biham E, Shamir A (1991) Differential cryptanalysis of des-like cryptosystems. J Cryptol 4:3\u201372","journal-title":"J Cryptol"},{"key":"184_CR5","doi-asserted-by":"crossref","unstructured":"Biham E, Biryukov A, Shamir A (1999) Cryptanalysis of skipjack reduced to 31 rounds using impossible differentials. In: Proceedings of the advances in cryptology-EUROCRYPT\u201999: international conference on the theory and application of cryptographic techniques Prague, Czech Republic, May 2\u20136, 1999. Springer, vol 18, pp 12\u201323","DOI":"10.1007\/3-540-48910-X_2"},{"key":"184_CR6","doi-asserted-by":"crossref","unstructured":"Bogdanov A, Knudsen LR, Leander G, Paar C, Poschmann A, Robshaw MJ, Seurin Y, Vikkelsoe C (2007) Present: an ultra-lightweight block cipher. In: Proceedings of the cryptographic hardware and embedded systems-CHES 2007: 9th international workshop, Vienna, Austria, September 10\u201313, 2007. Springer, vol 9, pp 450\u2013466","DOI":"10.1007\/978-3-540-74735-2_31"},{"key":"184_CR7","doi-asserted-by":"crossref","unstructured":"Boura C, Naya-Plasencia M, Suder V (2014) Scrutinizing and improving impossible differential attacks: applications to CLEFIA, Camellia, LBlock and Simon (full version). Ph.D. thesis, IACR cryptology ePrint archive","DOI":"10.1007\/978-3-662-45611-8_10"},{"key":"184_CR8","unstructured":"Cui T, Chen S, Jia K, Fu K, Wang M (2016) New automatic search tool for impossible differentials and zero-correlation linear approximations. Cryptology ePrint archive"},{"issue":"16","key":"184_CR9","doi-asserted-by":"publisher","first-page":"13014","DOI":"10.1109\/JIOT.2021.3064203","volume":"8","author":"Y Guo","year":"2021","unstructured":"Guo Y, Li L, Liu B (2021) Shadow: a lightweight block cipher for IoT nodes. IEEE Internet Things J 8(16):13014\u201313023","journal-title":"IEEE Internet Things J"},{"key":"184_CR10","doi-asserted-by":"crossref","unstructured":"Hong D, Sung J, Hong S, Lim J, Lee S, Koo BS, Lee C, Chang D, Lee J, Jeong K et al (2006) Hight: a new block cipher suitable for low-resource device. In: Proceedings of the Cryptographic hardware and embedded systems-CHES 2006: 8th international workshop, Yokohama, Japan, October 10\u201313, 2006. Springer, vol 8, pp 46\u201359","DOI":"10.1007\/11894063_4"},{"key":"184_CR11","doi-asserted-by":"crossref","unstructured":"Hu X, Li Y, Jiao L, Tian S, Wang M (2020) Mind the propagation of states: new automatic search tool for impossible differentials and impossible polytopic transitions. In: Proceedings of the advances in cryptology\u2014ASIACRYPT 2020: 26th international conference on the theory and application of cryptology and information security, Daejeon, South Korea, December 7\u201311, 2020, Part I 26. Springer, pp 415\u2013445","DOI":"10.1007\/978-3-030-64837-4_14"},{"key":"184_CR12","doi-asserted-by":"crossref","unstructured":"Kaur M, Yadav T, Kumar M, Dey D (2023) Full-round differential attack on ULC and LICID block ciphers designed for IoT. Cryptology ePrint archive","DOI":"10.21203\/rs.3.rs-1606963\/v1"},{"issue":"2","key":"184_CR14","first-page":"216","volume":"258","author":"L Knudsen","year":"1998","unstructured":"Knudsen L (1998) Deal-a 128-bit block cipher. Complexity 258(2):216","journal-title":"Complexity"},{"key":"184_CR15","doi-asserted-by":"crossref","unstructured":"K\u00f6lbl S, Leander G, Tiessen T (2015) Observations on the SIMON block cipher family. In: Proceedings of the advances in cryptology\u2014CRYPTO 2015: 35th annual cryptology conference, Santa Barbara, CA, USA, August 16\u201320, 2015, Part I. Springer, vol 35, pp 161\u2013185","DOI":"10.1007\/978-3-662-47989-6_8"},{"key":"184_CR16","doi-asserted-by":"crossref","unstructured":"Kumar M, Yadav T (2022) MILP based differential attack on round reduced warp. In: Proceedings of the security, privacy, and applied cryptography engineering: 11th international conference, SPACE 2021, Kolkata, India, December 10\u201313, 2021. Springer, pp 42\u201359","DOI":"10.1007\/978-3-030-95085-9_3"},{"key":"184_CR18","doi-asserted-by":"crossref","unstructured":"Matsui M (1994) Linear cryptanalysis method for DES cipher. In: Proceedings of the advances in cryptology-EUROCRYPT\u201993: workshop on the theory and application of cryptographic techniques Lofthus, Norway, May 23\u201327, 1993. Springer, vol 12, pp 386\u2013397","DOI":"10.1007\/3-540-48285-7_33"},{"key":"184_CR19","doi-asserted-by":"crossref","unstructured":"Mouha N, Wang Q, Gu D, Preneel B (2012) Differential and linear cryptanalysis using mixed-integer linear programming. In: Information security and cryptology: 7th international conference, Inscrypt 2011, Beijing, China, November 30\u2013December 3, 2011. Revised selected papers 7. Springer, pp 57\u201376","DOI":"10.1007\/978-3-642-34704-7_5"},{"key":"184_CR20","doi-asserted-by":"crossref","unstructured":"Sasaki Y, Todo Y (2017) New impossible differential search tool from design and cryptanalysis aspects: Revealing structural properties of several ciphers. In: Advances in Cryptology\u2013EUROCRYPT 2017: 36th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Paris, France, April 30\u2013May 4, 2017, Proceedings, Part III 36, pp. 185\u2013215. Springer","DOI":"10.1007\/978-3-319-56617-7_7"},{"key":"184_CR21","doi-asserted-by":"crossref","unstructured":"Standaert FX, Piret G, Gershenfeld N, Quisquater JJ (2006) SEA: a scalable encryption algorithm for small embedded applications. In: Proceedings of the smart card research and advanced applications: 7th IFIP WG 8.8\/11.2 international conference, CARDIS 2006, Tarragona, Spain, April 19\u201321, 2006. Springer, vol 7, pp 222\u2013236","DOI":"10.1007\/11733447_16"},{"key":"#cr-split#-184_CR22.1","doi-asserted-by":"crossref","unstructured":"Sun S, Hu L, Wang P, Qiao K, Ma X, Song L (2014) Automatic security evaluation and (related-key) differential characteristic search: application to SIMON, PRESENT, LBlock, DES","DOI":"10.1007\/978-3-662-45611-8_9"},{"key":"#cr-split#-184_CR22.2","unstructured":"(l) and other bit-oriented block ciphers. In: Proceedings of the advances in cryptology-ASIACRYPT 2014: 20th international conference on the theory and application of cryptology and information security, Kaoshiung, Taiwan, ROC, December 7-11, 2014, Part I. Springer, vol 20, pp 158-178"},{"key":"184_CR23","doi-asserted-by":"crossref","unstructured":"Sun L, Wang M (2023) SoK: modeling for large s-boxes oriented to differential probabilities and linear correlations. IACR Trans Symmetric Cryptol 111\u2013151","DOI":"10.46586\/tosc.v2023.i1.111-151"},{"key":"184_CR24","doi-asserted-by":"crossref","unstructured":"Sun L, Wang W, Wang M (2017) Automatic search of bit-based division property for ARX ciphers and word-based division property. In: Proceedings of the advances in cryptology\u2014ASIACRYPT 2017: 23rd international conference on the theory and applications of cryptology and information security, Hong Kong, China, December 3\u20137, 2017, Part I. Springer, vol 23, pp 128\u2013157","DOI":"10.1007\/978-3-319-70694-8_5"},{"key":"184_CR25","doi-asserted-by":"crossref","unstructured":"Sun L, Wang W, Wang M (2021) Accelerating the search of differential and linear characteristics with the sat method. IACR Trans Symmetric Cryptol 269\u2013315","DOI":"10.46586\/tosc.v2021.i1.269-315"},{"key":"184_CR27","doi-asserted-by":"crossref","unstructured":"Wu W, Zhang L (2011) LBlock: a lightweight block cipher. In: Proceedings of the applied cryptography and network security: 9th international conference, ACNS 2011, Nerja, Spain, June 7\u201310, 2011. Springer, vol 9, pp 327\u2013344","DOI":"10.1007\/978-3-642-21554-4_19"},{"key":"184_CR28","doi-asserted-by":"crossref","unstructured":"Zhu B, Dong X, Yu H (2019) MILP-based differential attack on round-reduced gift. In: Proceedings of the topics in cryptology\u2014CT-RSA 2019: the cryptographers\u2019 track at the RSA conference 2019, San Francisco, CA, USA, March 4\u20138, 2019. Springer, pp 372\u2013390","DOI":"10.1007\/978-3-030-12612-4_19"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00184-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-023-00184-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00184-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,12,7]],"date-time":"2023-12-07T02:03:44Z","timestamp":1701914624000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-023-00184-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,7]]},"references-count":26,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["184"],"URL":"https:\/\/doi.org\/10.1186\/s42400-023-00184-7","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,7]]},"assertion":[{"value":"6 April 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 August 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 December 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing fnancial interests or personal relationships that could have appeared to infuence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"52"}}