{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T06:08:48Z","timestamp":1741068528841,"version":"3.38.0"},"reference-count":20,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T00:00:00Z","timestamp":1741046400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T00:00:00Z","timestamp":1741046400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Yunnan Key Laboratory of Blockchain Application Technology","award":["202305AG340008"],"award-info":[{"award-number":["202305AG340008"]}]},{"name":"Natural Science Foundation of Beijing Province","award":["4234084"],"award-info":[{"award-number":["4234084"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>SAILFISH-I, first proposed by Agarwal et al. in 2022, is a lightweight block cipher with a typical Feistel structure, which is evaluated for the first time in this paper for its resistance to integral cryptanalysis. Firstly, the S-box and the overall structure are modeled based on the MILP method. We can find 11-round integral distinguishers for SAILFISH-I, which further reduces the number of active bits to find 10-round integral distinguishers with 57 active bits. Secondly, one round is added in front of the distinguisher and three rounds are added at the back, while the partial sum technique is used for the first time to recover the key of SAILFISH-I for 14-round. In the whole process of integral attack, the required data complexity is adding one round in front of the distinguisher and three rounds at the same time, using the partial sum technique. For the key recovery of SAILFISH-I for the first time, the required data complexity is <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$2^{59}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msup>\n                    <mml:mn>2<\/mml:mn>\n                    <mml:mn>59<\/mml:mn>\n                  <\/mml:msup>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> chosen plaintexts, the time complexity is <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$2^{59.42}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msup>\n                    <mml:mn>2<\/mml:mn>\n                    <mml:mrow>\n                      <mml:mn>59.42<\/mml:mn>\n                    <\/mml:mrow>\n                  <\/mml:msup>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> times 14-round of encryption, and the memory complexity is <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$2^{57}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msup>\n                    <mml:mn>2<\/mml:mn>\n                    <mml:mn>57<\/mml:mn>\n                  <\/mml:msup>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula>. Finally, based on the 14-round key recovery attack, the guessing order of key bits is optimized, and the 18-round key recovery attack on SAILFISH-I is completed for the first time. Throughout the integral attack process, we recover 97 bits of key with <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$2^{61.64}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msup>\n                    <mml:mn>2<\/mml:mn>\n                    <mml:mrow>\n                      <mml:mn>61.64<\/mml:mn>\n                    <\/mml:mrow>\n                  <\/mml:msup>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> chosen plaintexts and <jats:inline-formula>\n              <jats:alternatives>\n                <jats:tex-math>$$2^{147.06}$$<\/jats:tex-math>\n                <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:msup>\n                    <mml:mn>2<\/mml:mn>\n                    <mml:mrow>\n                      <mml:mn>147.06<\/mml:mn>\n                    <\/mml:mrow>\n                  <\/mml:msup>\n                <\/mml:math>\n              <\/jats:alternatives>\n            <\/jats:inline-formula> time complexity of the 18-round encryption. Moreover, if we can use the balanced bits fully, then the number of recoverable key bits will rise to 129.<\/jats:p>","DOI":"10.1186\/s42400-024-00302-z","type":"journal-article","created":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T02:02:11Z","timestamp":1741053731000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Integral cryptanalysis on reduce-round SAILFISH-I"],"prefix":"10.1186","volume":"8","author":[{"given":"Yanjun","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lixian","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yiping","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yani","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,3,4]]},"reference":[{"key":"302_CR1","doi-asserted-by":"publisher","first-page":"203747","DOI":"10.1109\/ACCESS.2020.3036589","volume":"8","author":"B Aboushosha","year":"2020","unstructured":"Aboushosha B, Ramadan RA, Dwivedi AD, El-Sayed A, Dessouky MM (2020) SLIM: a lightweight block cipher for internet of health things. IEEE Access 8:203747\u2013203757","journal-title":"IEEE Access"},{"key":"302_CR2","doi-asserted-by":"publisher","first-page":"535","DOI":"10.1007\/978-3-030-81652-0_21","volume-title":"Selected areas in cryptography","author":"S Banik","year":"2021","unstructured":"Banik S, Bao Z, Isobe T, Kubo H, Liu F, Minematsu K, Sakamoto K, Shibata N, Shigeri M (2021) Warp\u202f: Revisiting GFN for lightweight 128-bit block cipher. In: Dunkelman O, Jacobson MJ Jr, O\u2019Flynn C (eds) Selected areas in cryptography. Springer, Cham, pp 535\u2013564"},{"key":"302_CR3","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/978-3-662-53008-5_5","volume-title":"Advances in cryptology - CRYPTO 2016","author":"C Beierle","year":"2016","unstructured":"Beierle C, Jean J, K\u00f6lbl S, Leander G, Moradi A, Peyrin T, Sasaki Y, Sasdrich P, Sim SM (2016) The skinny family of block ciphers and its low-latency variant mantis. In: Robshaw M, Katz J (eds) Advances in cryptology - CRYPTO 2016. Springer, Berlin, Heidelberg, pp 123\u2013153"},{"key":"302_CR4","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-021-00970-9","author":"S Chen","year":"2022","unstructured":"Chen S, Fan Y, Sun L, Fu Y, Zhou H, Li Y, Wang M, Wang W, Guo C (2022) Sand: an and-rx feistel lightweight block cipher supporting s-box-based security evaluations. Des Code Cryptogr DOIurl. https:\/\/doi.org\/10.1007\/s10623-021-00970-9","journal-title":"Des Code Cryptogr DOIurl"},{"key":"302_CR5","doi-asserted-by":"crossref","unstructured":"Agarwal D, Gurele S, Lamkuche HS (2022) Sailfish-i: A lightweight block cipher for cloud-enabled fog devices. In: 2022 IEEE 6th Conference on Information and Communication Technology (CICT), pp. 1\u20136 10.1109\/CICT56698.2022.9997844","DOI":"10.1109\/CICT56698.2022.9997844"},{"key":"302_CR6","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1007\/3-540-45661-9_9","volume-title":"Fast software encryption","author":"L Knudsen","year":"2002","unstructured":"Knudsen L, Wagner D (2002) Integral cryptanalysis. In: Daemen J, Rijmen V (eds) Fast software encryption. Springer, Berlin, Heidelberg, pp 112\u2013127"},{"key":"302_CR7","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/3-540-44706-7_15","volume-title":"Fast software encryption","author":"N Ferguson","year":"2001","unstructured":"Ferguson N, Kelsey J, Lucks S, Schneier B, Stay M, Wagner D, Whiting D (2001) Improved cryptanalysis of rijndael. In: Goos G, Hartmanis J, Leeuwen J, Schneier B (eds) Fast software encryption. Springer, Berlin, Heidelberg, pp 213\u2013230"},{"key":"302_CR8","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1007\/978-3-319-12280-9_5","volume-title":"Cryptology and network security","author":"Y Todo","year":"2014","unstructured":"Todo Y, Aoki K (2014) Fft key recovery for integral attack. In: Gritzalis D, Kiayias A, Askoxylakis I (eds) Cryptology and network security. Springer, Cham, pp 64\u201381"},{"key":"302_CR9","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1007\/978-3-662-46800-5_12","volume-title":"Advances in cryptology - EUROCRYPT 2015","author":"Y Todo","year":"2015","unstructured":"Todo Y (2015) Structural evaluation by generalized integral property. In: Oswald E, Fischlin M (eds) Advances in cryptology - EUROCRYPT 2015. Springer, Berlin, Heidelberg, pp 287\u2013314"},{"key":"302_CR10","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/978-3-662-52993-5_18","volume-title":"Fast software encryption","author":"Y Todo","year":"2016","unstructured":"Todo Y, Morii M (2016) Bit-based division property and application to Simon family. In: Peyrin T (ed) Fast software encryption. Springer, Berlin, Heidelberg, pp 357\u2013377"},{"key":"302_CR11","doi-asserted-by":"publisher","first-page":"648","DOI":"10.1007\/978-3-662-53887-6_24","volume-title":"Advances in cryptology - ASIACRYPT 2016","author":"Z Xiang","year":"2016","unstructured":"Xiang Z, Zhang W, Bao Z, Lin D (2016) Applying milp method to searching integral distinguishers based on division property for 6 lightweight block ciphers. In: Cheon JH, Takagi T (eds) Advances in cryptology - ASIACRYPT 2016. Springer, Berlin, Heidelberg, pp 648\u2013678"},{"key":"302_CR12","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1007\/978-3-319-70694-8_5","volume-title":"Advances in cryptology - ASIACRYPT 2017","author":"L Sun","year":"2017","unstructured":"Sun L, Wang W, Wang M (2017) Automatic search of bit-based division property for ARX ciphers and word-based division property. In: Takagi T, Peyrin T (eds) Advances in cryptology - ASIACRYPT 2017. Springer, Cham, pp 128\u2013157"},{"key":"302_CR13","doi-asserted-by":"publisher","first-page":"398","DOI":"10.1007\/978-3-030-34618-8_14","volume-title":"Advances in cryptology - ASIACRYPT 2019","author":"S Wang","year":"2019","unstructured":"Wang S, Hu B, Guan J, Zhang K, Shi T (2019) Milp-aided method of searching division property using three subsets and applications. In: Galbraith SD, Moriai S (eds) Advances in cryptology - ASIACRYPT 2019. Springer, Cham, pp 398\u2013427"},{"issue":"3","key":"302_CR14","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1007\/s00145-021-09383-2","volume":"34","author":"Y Hao","year":"2021","unstructured":"Hao Y, Leander G, Meier W, Todo Y, Wang Q (2021) Modeling for three-subset division property without unknown subset. J Cryptol 34(3):22. https:\/\/doi.org\/10.1007\/s00145-021-09383-2","journal-title":"J Cryptol"},{"key":"302_CR15","doi-asserted-by":"publisher","first-page":"173","DOI":"10.46586\/tosc.v2020.i4.173-194","volume":"2020","author":"P Derbez","year":"2020","unstructured":"Derbez P, Fouque PA (2020) Increasing precision of division property. IACR Trans Symmetric Cryptol 2020:173\u2013194","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"302_CR16","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1007\/978-3-030-92062-3_12","volume-title":"Advances in cryptology - ASIACRYPT 2021","author":"A Udovenko","year":"2021","unstructured":"Udovenko A (2021) Convexity of division property transitions: Theory, algorithms and compact models. In: Tibouchi M, Wang H (eds) Advances in cryptology - ASIACRYPT 2021. Springer, Cham, pp 332\u2013361"},{"key":"302_CR17","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1007\/978-3-642-23951-9_22","volume-title":"Cryptographic hardware and embedded systems - CHES 2011","author":"J Guo","year":"2011","unstructured":"Guo J, Peyrin T, Poschmann A, Robshaw M (2011) The led block cipher. In: Preneel B, Takagi T (eds) Cryptographic hardware and embedded systems - CHES 2011. Springer, Berlin, Heidelberg, pp 326\u2013341"},{"key":"302_CR18","doi-asserted-by":"publisher","first-page":"289","DOI":"10.46586\/tosc.v2022.i2.289-321","volume":"2022","author":"P Derbez","year":"2022","unstructured":"Derbez P, Lambin B (2022) Fast milp models for division property. IACR Trans Symmetric Cryptol 2022:289\u2013321","journal-title":"IACR Trans Symmetric Cryptol"},{"issue":"05","key":"302_CR19","first-page":"627","volume":"6","author":"F Shang","year":"2019","unstructured":"Shang F, Shen X, Liu G, Li C (2019) Integral cryptanalysis on puffin based on milp. J Cryptol Res 6(05):627\u2013638","journal-title":"J Cryptol Res"},{"key":"302_CR20","volume-title":"Attack method and case analysis of block cipher","author":"C Li","year":"2010","unstructured":"Li C, Sun B, Li R (2010) Attack method and case analysis of block cipher. Science China Press, China"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-024-00302-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-024-00302-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-024-00302-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T02:02:22Z","timestamp":1741053742000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-024-00302-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,4]]},"references-count":20,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["302"],"URL":"https:\/\/doi.org\/10.1186\/s42400-024-00302-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,4]]},"assertion":[{"value":"29 March 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 June 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 March 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The datasets generated during analysed during the current study are not publicly available but are available from the corresponding author on reasonable request.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Availability of data and materials:"}},{"value":"This work was supported by the Fund of Yunnan Key Laboratory of Blockchain Application Technology under Grant (202305AG340008) and Natural Science Foundation of Beijing Province under Grant (No.4234084).","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Funding:"}},{"value":"We declare that there are no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests:"}}],"article-number":"16"}}