{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,17]],"date-time":"2025-12-17T00:04:07Z","timestamp":1765929847558,"version":"3.48.0"},"reference-count":33,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,12,17]],"date-time":"2025-12-17T00:00:00Z","timestamp":1765929600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,12,17]],"date-time":"2025-12-17T00:00:00Z","timestamp":1765929600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"the National Key Research and Development Program of China","award":["No. 2022YFF0604702"],"award-info":[{"award-number":["No. 2022YFF0604702"]}]},{"name":"Guangdong-Foshan Joint Fund Project","award":["2022A1515140096"],"award-info":[{"award-number":["2022A1515140096"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The  cipher is a lightweight tweakable block cipher introduced at FSE 2019. Its design aims to incorporate countermeasures against Differential Fault Attacks at the algorithmic level. The cipher employs a lightweight and involutory S-box along with a simple linear layer, enabling efficient encryption and decryption operations. In particular,  utilizes a straightforward tweakey schedule that generates four 64-bit round tweakeys, which are reused throughout the encryption process. Despite its lightweight design, the resistance of  against impossible differential analysis has not been thoroughly evaluated, with limited attention from cryptanalysts in this regard. Hence, this paper presents a comprehensive analysis of  specifically targeting its resistance to impossible differential cryptanalysis. By employing an Satisfiability Modulo Theory (SMT) based automatic search tool, we successfully identify both 12-round related-tweak impossible differential distinguishers and 15-round related-tweakey impossible differential distinguishers for , marking the first discovery of such distinguishers for this cipher. Our results indicate that the tweak in  enhances the cipher\u2019s flexibility, provided it receives appropriate attention. In addition, we conduct key-recovery attacks on reduced-round , successfully recovering the 128-bit keys for 20-round, 21-round, and 23-round variants. Based on our comprehensive analysis and experimental results, we conclude that  demonstrates effective resistance against impossible differential cryptanalysis.<\/jats:p>","DOI":"10.1186\/s42400-025-00393-2","type":"journal-article","created":{"date-parts":[[2025,12,17]],"date-time":"2025-12-17T00:01:23Z","timestamp":1765929683000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Impossible differential cryptanalysis of lightweight tweakable block cipher CRAFT"],"prefix":"10.1186","volume":"8","author":[{"given":"Fen","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2551-2737","authenticated-orcid":false,"given":"Yongqiang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huiqin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Li","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhengbin","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenyin","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,12,17]]},"reference":[{"issue":"3","key":"393_CR1","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1109\/TC.2019.2948617","volume":"69","author":"A Aghaie","year":"2020","unstructured":"Aghaie A, Moradi A, Rasoolzadeh S, Shahmirzadi AR, Schellenberg F, Schneider T (2020) Impeccable circuits. IEEE Trans Comput 69(3):361\u2013376. https:\/\/doi.org\/10.1109\/TC.2019.2948617","journal-title":"IEEE Trans Comput"},{"key":"393_CR2","doi-asserted-by":"publisher","unstructured":"Banik S, Bogdanov A, Isobe T, Shibutani K, Hiwatari H, Akishita T, Regazzoni F (2015) Midori: a block cipher for low energy. In: Advances in cryptology\u2013ASIACRYPT 2015: 21st international conference on the theory and application of cryptology and information security, Auckland, New Zealand, November 29\u2013December 3, 2015, Proceedings, Part II 21. Lecture Notes in Computer Science, vol. 9453, pp. 411\u2013436. https:\/\/doi.org\/10.1007\/978-3-662-48800-3_17 . Springer","DOI":"10.1007\/978-3-662-48800-3_17"},{"issue":"1","key":"393_CR3","doi-asserted-by":"publisher","first-page":"5","DOI":"10.13154\/tosc.v2019.i1.5-45","volume":"2019","author":"C Beierle","year":"2019","unstructured":"Beierle C, Leander G, Moradi A, Rasoolzadeh S (2019) Craft: lightweight tweakable block cipher with efficient protection against DFA attacks. IACR Trans Symmetric Cryptol 2019(1):5\u201345. https:\/\/doi.org\/10.13154\/tosc.v2019.i1.5-45","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"393_CR4","doi-asserted-by":"publisher","unstructured":"Biham E, Shamir A (1997) Differential fault analysis of secret key cryptosystems. In: Advances in Cryptology\u2013CRYPTO\u201997: 17th annual international cryptology conference Santa Barbara, California, USA August 17\u201321, 1997 Proceedings 17. Lecture notes in computer science, vol. 1294, pp. 513\u2013525. https:\/\/doi.org\/10.1007\/BFb0052259 . Springer","DOI":"10.1007\/BFb0052259"},{"key":"393_CR5","doi-asserted-by":"publisher","unstructured":"Biham E, Biryukov A, Shamir A (1999) Cryptanalysis of skipjack reduced to 31 rounds using impossible differentials. In: International conference on the theory and applications of cryptographic techniques, pp. 12\u201323. https:\/\/doi.org\/10.1007\/3-540-48910-X_2 . Springer","DOI":"10.1007\/3-540-48910-X_2"},{"key":"393_CR6","doi-asserted-by":"publisher","unstructured":"Boura C, Naya-Plasencia M, Suder V (2014) Scrutinizing and improving impossible differential attacks: applications to clefia, camellia, lblock and simon. In: Advances in cryptology\u2013ASIACRYPT 2014: 20th international conference on the theory and application of cryptology and information security, Kaoshiung, Taiwan, ROC, December 7-11, 2014. Proceedings, Part I 20. Lecture notes in computer science, vol. 8873, pp. 179\u2013199. https:\/\/doi.org\/10.1007\/978-3-662-45611-8_10 . Springer","DOI":"10.1007\/978-3-662-45611-8_10"},{"key":"393_CR7","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-018-1506-4","author":"T Cui","year":"2021","unstructured":"Cui T, Chen S, Jia K, Fu K, Wang M (2021) New automatic search tool for impossible differentials and zero-correlation linear approximations. Sci China Inf Sci. https:\/\/doi.org\/10.1007\/s11432-018-1506-4","journal-title":"Sci China Inf Sci"},{"key":"393_CR8","doi-asserted-by":"publisher","unstructured":"De\u00a0Canniere C, Dunkelman O, Kne\u017eevi\u0107 M (2009) Katan and ktantan: a family of small and efficient hardware-oriented block ciphers. In: Cryptographic hardware and embedded systems - CHES 2009. Lecture notes in computer science, vol. 5747, pp. 272\u2013288. Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-642-04138-9_20 . Springer","DOI":"10.1007\/978-3-642-04138-9_20"},{"key":"393_CR9","doi-asserted-by":"publisher","unstructured":"ElSheikh M, Youssef AM (2019) Related-key differential cryptanalysis of full round craft. In: security, privacy, and applied cryptography engineering: 9th international conference, SPACE 2019, Gandhinagar, India, December 3\u20137, 2019, proceedings. Lecture notes in computer science, vol. 11947, pp. 50\u201366. https:\/\/doi.org\/10.1007\/978-3-030-35869-3_6 . Springer","DOI":"10.1007\/978-3-030-35869-3_6"},{"issue":"3","key":"393_CR10","doi-asserted-by":"publisher","first-page":"119","DOI":"10.13154\/tosc.v2020.i3.119-151","volume":"202","author":"H Guo","year":"2020","unstructured":"Guo H, Sun S, Shi D, Sun L, Sun Y, Hu L, Wang M (2020) Differential attacks on craft exploiting the involutory s-boxes and tweak additions. Cryptol ePrint Arch 202(3):119\u2013151. https:\/\/doi.org\/10.13154\/tosc.v2020.i3.119-151","journal-title":"Cryptol ePrint Arch"},{"key":"393_CR11","doi-asserted-by":"publisher","DOI":"10.46586\/tosc.v2021.i2.140-198","author":"H Hadipour","year":"2021","unstructured":"Hadipour H, Bagheri N, Song L (2021) Improved rectangle attacks on skinny and craft. IACR Trans Symmetric Cryptol. https:\/\/doi.org\/10.46586\/tosc.v2021.i2.140-198","journal-title":"IACR Trans Symmetric Cryptol"},{"issue":"4","key":"393_CR12","doi-asserted-by":"publisher","first-page":"290","DOI":"10.13154\/tosc.v2019.i4.290-317","volume":"209","author":"H Hadipour","year":"2019","unstructured":"Hadipour H, Sadeghi S, Niknam MM, Song L, Bagheri N (2019) Comprehensive security analysis of craft. IACR Trans Symmetric Cryptol 209(4):290\u2013317. https:\/\/doi.org\/10.13154\/tosc.v2019.i4.290-317","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"393_CR13","doi-asserted-by":"publisher","unstructured":"Hadipour H, Sadeghi S, Eichlseder M (2023) Finding the impossible: automated search for full impossible-differential, zero-correlation, and integral attacks. In: 42nd Annual international conference on the theory and applications of cryptographic techniques: EUROCRYPT 2023, pp. 128\u2013157. https:\/\/doi.org\/10.1007\/978-3-031-30634-1_5 . Springer","DOI":"10.1007\/978-3-031-30634-1_5"},{"key":"393_CR14","doi-asserted-by":"publisher","unstructured":"Hu X, Li Y, Jiao L, Tian S, Wang M (2020) Mind the propagation of states: new automatic search tool for impossible differentials and impossible polytopic transitions. In: advances in cryptology\u2013ASIACRYPT 2020: 26th international conference on the theory and application of cryptology and information security, Daejeon, South Korea, December 7\u201311, 2020, Proceedings, Part I 26, pp. 415\u2013445. https:\/\/doi.org\/10.1007\/978-3-030-64837-4_14 . Springer","DOI":"10.1007\/978-3-030-64837-4_14"},{"issue":"5","key":"393_CR15","doi-asserted-by":"publisher","first-page":"988","DOI":"10.1016\/j.disc.2009.10.019","volume":"310","author":"J Kim","year":"2010","unstructured":"Kim J, Hong S, Lim J (2010) Impossible differential cryptanalysis using matrix method. Discrete Math 310(5):988\u20131002. https:\/\/doi.org\/10.1016\/j.disc.2009.10.019","journal-title":"Discrete Math"},{"key":"393_CR16","unstructured":"Knudsen L (1998) Deal - a 128-bit block cipher. NISI AES Proposal"},{"key":"393_CR17","doi-asserted-by":"crossref","unstructured":"Kocher PC (1996) Timing attacks on implementations of diffie-hellman, rsa, dss, and other systems. In: Advances in Cryptology\u2013CRYPTO\u201996: 16th annual international cryptology conference Santa Barbara, California, USA August 18\u201322, 1996 proceedings 16, pp. 104\u2013113. Springer","DOI":"10.1007\/3-540-68697-5_9"},{"key":"393_CR18","doi-asserted-by":"publisher","unstructured":"Kocher P, Jaffe J, Jun B (1996) Differential power analysis. In: Advances in Cryptology\u2013CRYPTO\u201999: 19th Annual International Cryptology Conference Santa Barbara, California, USA, August 15\u201319, 1999 Proceedings 19. Lecture notes in computer science, vol. 1109, pp. 104\u2013113. https:\/\/doi.org\/10.1007\/3-540-68697-5_9 . Springer","DOI":"10.1007\/3-540-68697-5_9"},{"key":"393_CR19","doi-asserted-by":"publisher","unstructured":"Krovetz T, Rogaway P (2011) The software performance of authenticated-encryption modes. In: fast software encryption: 18th international workshop, FSE 2011, Lyngby, Denmark, February 13-16, 2011, Revised selected papers 18. Lecture notes in computer science, vol. 6733, pp. 306\u2013327. https:\/\/doi.org\/10.1007\/978-3-642-21702-9_18 . Springer","DOI":"10.1007\/978-3-642-21702-9_18"},{"issue":"1","key":"393_CR20","doi-asserted-by":"publisher","first-page":"38","DOI":"10.46586\/tosc.v2022.i1.38-63","volume":"2022","author":"G Leander","year":"2022","unstructured":"Leander G, Rasoolzadeh S (2022) Weak tweak-keys for the CRAFT block cipher. IACR Trans Symmetric Cryptol 2022(1):38\u201363","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"393_CR21","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-018-9772-0","author":"Y Liu","year":"2021","unstructured":"Liu Y, Liang H, Li M, Huang L, Hu K, Yang C, Wang M (2021) STP models of optimal differential and linear trail for s-box based ciphers. Sci China Inf Sci. https:\/\/doi.org\/10.1007\/s11432-018-9772-0","journal-title":"Sci China Inf Sci"},{"key":"393_CR22","doi-asserted-by":"publisher","unstructured":"Liu Y, Wang Q, Rijmen V (2016) Automatic search of linear trails in arx with applications to speck and chaskey. In: applied cryptography and network security: 14th International conference, ACNS 2016, Guildford, UK, June 19-22, 2016. Proceedings 14. lecture notes in computer science, vol. 9696, pp. 485\u2013499. https:\/\/doi.org\/10.1007\/978-3-319-39555-5_26 . Springer","DOI":"10.1007\/978-3-319-39555-5_26"},{"issue":"5","key":"393_CR23","doi-asserted-by":"publisher","first-page":"1179","DOI":"10.1007\/s10623-022-01034-2","volume":"90","author":"Z Lu","year":"2022","unstructured":"Lu Z, Mesnager S, Cui T, Fan Y, Wang M (2022) An STP-based model toward designing s-boxes with good cryptographic properties. Des, Codes Cryptogr 90(5):1179\u20131202. https:\/\/doi.org\/10.1007\/s10623-022-01034-2","journal-title":"Des, Codes Cryptogr"},{"key":"393_CR24","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.ins.2013.08.051","volume":"263","author":"Y Luo","year":"2014","unstructured":"Luo Y, Lai X, Wu Z, Gong G (2014) A unified method for finding impossible differentials of block cipher structures. Inf Sci 263:211\u2013220. https:\/\/doi.org\/10.1016\/j.ins.2013.08.051","journal-title":"Inf Sci"},{"issue":"12","key":"393_CR25","doi-asserted-by":"publisher","first-page":"1813","DOI":"10.1093\/comjnl\/bxaa004","volume":"63","author":"AE Moghaddam","year":"2019","unstructured":"Moghaddam AE, Ahmadian Z (2019) New automatic search method for truncated-differential characteristics: application to midori, skinny and craft. Comput J 63(12):1813\u20131825. https:\/\/doi.org\/10.1093\/comjnl\/bxaa004","journal-title":"Comput J"},{"key":"393_CR26","doi-asserted-by":"publisher","unstructured":"Mouha N, Wang Q, Gu D, Preneel B (2012) Differential and linear cryptanalysis using mixed-integer linear programming. In: information security and cryptology: 7th International conference, Inscrypt 2011, Beijing, China, November 30\u2013December 3, 2011. Revised Selected Papers 7, pp. 57\u201376. https:\/\/doi.org\/10.1007\/978-3-642-34704-7_5 . Springer","DOI":"10.1007\/978-3-642-34704-7_5"},{"key":"393_CR27","doi-asserted-by":"publisher","unstructured":"Peyrin T, Seurin Y (2016) Counter-in-tweak: authenticated encryption modes for tweakable block ciphers. In: Advances in cryptology\u2013CRYPTO 2016: 36th annual international cryptology conference, Santa Barbara, CA, USA, August 14-18, 2016, Proceedings, Part I. Lecture Notes in Computer Science, vol. 9814, pp. 33\u201363. https:\/\/doi.org\/10.1007\/978-3-662-53018-4_2 . Springer","DOI":"10.1007\/978-3-662-53018-4_2"},{"key":"393_CR28","doi-asserted-by":"publisher","unstructured":"Sasaki Y, Todo Y (2017) New impossible differential search tool from design and cryptanalysis aspects: revealing structural properties of several ciphers. In: Advances in cryptology\u2013EUROCRYPT 2017: 36th Annual international conference on the theory and applications of cryptographic techniques, Paris, France, April 30\u2013May 4, 2017, Proceedings, Part III 36, pp. 185\u2013215. https:\/\/doi.org\/10.1007\/978-3-319-56617-7_7 . Springer","DOI":"10.1007\/978-3-319-56617-7_7"},{"key":"393_CR29","doi-asserted-by":"publisher","unstructured":"Shibutani K, Isobe T, Hiwatari H, Mitsuda A, Akishita T, Shirai T (2011) Piccolo: an ultra-lightweight blockcipher. In: cryptographic hardware and embedded systems \u2013 CHES 2011. Lecture notes in computer science, vol. 6917, pp. 342\u2013357. Berlin, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-642-23951-9_23 . Springer","DOI":"10.1007\/978-3-642-23951-9_23"},{"key":"393_CR30","doi-asserted-by":"publisher","unstructured":"Song L, Zhang N, Yang Q, Shi D, Zhao J, Hu L, Weng J (2023) Optimizing rectangle attacks: a unified and generic framework for key recovery. In: Advances in cryptology\u2013ASIACRYPT 2022: 28th international conference on the theory and application of cryptology and information security, Taipei, Taiwan, December 5\u20139, 2022, proceedings, Part I. Lecture notes in computer science, vol. 13791, pp. 410\u2013440. https:\/\/doi.org\/10.1007\/978-3-031-22963-3_14 . Springer","DOI":"10.1007\/978-3-031-22963-3_14"},{"issue":"1","key":"393_CR31","doi-asserted-by":"publisher","first-page":"269","DOI":"10.46586\/tosc.v2021.i1.269-315","volume":"201","author":"L Sun","year":"2021","unstructured":"Sun L, Wang W, Wang M (2021) Accelerating the search of differential and linear characteristics with the sat method. IACR Trans Symmetric Cryptol 201(1):269\u2013315. https:\/\/doi.org\/10.46586\/tosc.v2021.i1.269-315","journal-title":"IACR Trans Symmetric Cryptol"},{"key":"393_CR32","doi-asserted-by":"publisher","unstructured":"Sun S, Hu L, Wang P, Qiao K, Ma X, Song L (2014) Automatic security evaluation and (related-key) differential characteristic search: application to simon, present, lblock, des (l) and other bit-oriented block ciphers. In: Advances in cryptology\u2013ASIACRYPT 2014: 20th international conference on the theory and application of cryptology and information security, Kaoshiung, Taiwan, ROC, December 7-11, 2014. Proceedings, Part I 20, pp. 158\u2013178. https:\/\/doi.org\/10.1007\/978-3-662-45611-8_9 . Springer","DOI":"10.1007\/978-3-662-45611-8_9"},{"key":"393_CR33","doi-asserted-by":"publisher","unstructured":"Wu S, Wang M (2012) Automatic search of truncated impossible differentials for word-oriented block ciphers. In: Progress in cryptology-INDOCRYPT 2012: 13th International conference on cryptology in India, Kolkata, India, December 9-12, 2012. Proceedings 13, pp. 283\u2013302. https:\/\/doi.org\/10.1007\/978-3-642-34931-7_17 . Springer","DOI":"10.1007\/978-3-642-34931-7_17"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00393-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00393-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00393-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,17]],"date-time":"2025-12-17T00:01:24Z","timestamp":1765929684000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00393-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,17]]},"references-count":33,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["393"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00393-2","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,17]]},"assertion":[{"value":"10 December 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 March 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"93"}}