{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T13:53:41Z","timestamp":1764251621111,"version":"build-2065373602"},"reference-count":33,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2020,4,1]],"date-time":"2020-04-01T00:00:00Z","timestamp":1585699200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61571063,61701141"],"award-info":[{"award-number":["61571063,61701141"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004826","name":"Natural Science Foundation of Beijing","doi-asserted-by":"publisher","award":["3182028"],"award-info":[{"award-number":["3182028"]}],"id":[{"id":"10.13039\/501100004826","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2017M611357"],"award-info":[{"award-number":["2017M611357"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Postdoctoral Science Foundation of Heilongjiang Province of China","award":["LBH-Z17045"],"award-info":[{"award-number":["LBH-Z17045"]}]},{"name":"Technology Bureau of Qiqihar City of Heilongjiang Province of China","award":["GYGG-201905"],"award-info":[{"award-number":["GYGG-201905"]}]},{"name":"Heilongjiang Province Intelligent Machine Research Institute project","award":["135409610"],"award-info":[{"award-number":["135409610"]}]},{"name":"Young Creative Talents Training Plan of General Universities of Heilongjiang Province of China","award":["UNPYSCT-2017152."],"award-info":[{"award-number":["UNPYSCT-2017152."]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Embedded encryption devices and smart sensors are vulnerable to physical attacks. Due to the continuous shrinking of chip size, laser injection, particle radiation and electromagnetic transient injection are possible methods that introduce transient multiple faults. In the fault analysis stage, the adversary is unclear about the actual number of faults injected. Typically, the single-nibble fault analysis encounters difficulties. Therefore, in this paper, we propose novel ciphertext-only impossible differentials that can analyze the number of random faults to six nibbles. We use the impossible differentials to exclude the secret key that definitely does not exist, and then gradually obtain the unique secret key through inverse difference equations. Using software simulation, we conducted 32,000 random multiple fault attacks on Midori. The experiments were carried out to verify the theoretical model of multiple fault attacks. We obtain the relationship between fault injection and information content. To reduce the number of fault attacks, we further optimized the fault attack method. The secret key can be obtained at least 11 times. The proposed ciphertext-only impossible differential analysis provides an effective method for random multiple faults analysis, which would be helpful for improving the security of block ciphers.<\/jats:p>","DOI":"10.3390\/s20071976","type":"journal-article","created":{"date-parts":[[2020,4,2]],"date-time":"2020-04-02T11:57:14Z","timestamp":1585828634000},"page":"1976","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["An Effective Simulation Analysis of Transient Electromagnetic Multiple Faults"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7693-7268","authenticated-orcid":false,"given":"Liang","family":"Dong","sequence":"first","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"},{"name":"Communication and Electronic Engineering Institute, Qiqihar University, Qiqihar 161006, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongxin","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9222-9424","authenticated-orcid":false,"given":"Shaofei","family":"Sun","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Zhu","sequence":"additional","affiliation":[{"name":"Communication and Electronic Engineering Institute, Qiqihar University, Qiqihar 161006, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaotong","family":"Cui","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1457-3646","authenticated-orcid":false,"given":"Bablu K.","family":"Ghosh","sequence":"additional","affiliation":[{"name":"Faculty of Engineering, University Malaysia Sabah, Kota Kinabalu 88400, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,4,1]]},"reference":[{"key":"ref_1","unstructured":"Jean-Jacques, Q., and David, S. (2000, January 20\u201324). Simple electromagnetic analysis for smart cards: New results. Proceedings of the Crypto 2000, Santa Barbara, CA, USA."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Ding, G.L., Chu, J., Yuan, L., and Zhao, Q. (2009, January 16\u201317). Correlation Electromagnetic Analysis for Cryptographic Device. Proceedings of the Pacific-Asia Conference on Circuits, Communications and Systems, Chengdu, China.","DOI":"10.1109\/PACCS.2009.144"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"De Mulder, E., Ors, S.B., Preneel, B., and Verbauwhede, I. (2006, January 24\u201326). Differential Electromagnetic Attack on an FPGA Implementation of Elliptic Curve Cryptosystems. Proceedings of the World Automation Congress, Budapest, Hungary.","DOI":"10.1109\/WAC.2006.375739"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Selmke, B., Brummer, S., Heyszl, J., and Sigl, G. (2015, January 4\u20136). Precise Laser Fault Injections into 90 nm and 45 nm SRAM-cells. Proceedings of the Smart Card Research and Advanced Application (CARDIS 2015), Bochum, Germany.","DOI":"10.1007\/978-3-319-31271-2_12"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Van Woudenberg, J.G.J., Witteman, M.F., and Menarini, F. (2011, January 28). Practical Optical Fault Injection on Secure Microcontrollers. Proceedings of the Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC 2011), Nara, Japan.","DOI":"10.1109\/FDTC.2011.12"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Dutertre, J.M., Beroulle, V., Candelier, P., De Castro, S., Faber, L.B., Flottes, M.L., Philippe, G., David, H., Regis, L., and Paolo, M. (2018, January 13). Laser Fault Injection at the CMOS 28 nm Technology Node: An Analysis of the Fault Model. Proceedings of the Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC 2018), Amsterdam, The Netherlands.","DOI":"10.1109\/FDTC.2018.00009"},{"key":"ref_7","unstructured":"Dehbaoui, A., Dutertre, J.M., Robisson, B., Orsatelli, P., Maurine, P., and Tria, A. (2012, March 05). Injection of Transient Faults Using Electromagnetic Pulses Practical Results on a Cryptographic System. Available online: https:\/\/eprint.iacr.org\/2012\/123.pdf."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Ordas, S., Guillaume-Sage, L., and Maurine, P. (2015, January 13). EM Injection: Fault Model and Locality. Proceedings of the Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC 2015), St. Malo, France.","DOI":"10.1109\/FDTC.2015.9"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Boneh, D., DeMillo, R.A., and Lipton, R.J. (1997, January 11\u201315). On the Importance of Checking Cryptographic Protocols for Faults. Proceedings of the International Conference on the Theory and Application of Cryptographic Techniques, Konstanz, Germany.","DOI":"10.1007\/3-540-69053-0_4"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1109\/TDSC.2015.2449849","article-title":"Impossible differential fault analysis on the LED lightweight cryptosystem in the vehicular ad\u2013hoc networks","volume":"13","author":"Li","year":"2016","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Chen, Z., Chen, H., and Wang, X. (2016, January 16\u201318). Cryptanalysis of Midori128 Using Impossible Differential Techniques. Proceedings of the 12th International Conference, ISPEC 2016, Zhangjiajie, China.","DOI":"10.1007\/978-3-319-49151-6_1"},{"key":"ref_12","first-page":"3","article-title":"Impossible differential cryptanalysis of reduced-round midori64 block cipher","volume":"10","author":"Shahmirzadi","year":"2018","journal-title":"ISC Int. J. Inf. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Zhao, X., Guo, S., Zhang, F., Shi, Z., Ma, C., and Wang, T. (2013, January 20). Improving and Evaluating Differential Fault Analysis on LED with Algebraic Techniques. Proceedings of the Workshop on Fault Diagnosis Tolerance Cryptography (FDTC 2013), Santa Barbara, CA, USA.","DOI":"10.1109\/FDTC.2013.14"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"32110","DOI":"10.1007\/s11432-017-9209-0","article-title":"Impossible meet-in-the-middle fault analysis on the LED lightweight cipher in VANETs","volume":"61","author":"Li","year":"2018","journal-title":"Sci. China Inf. Sci."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Cheng, W., Zhou, Y., and Sauvage, L. (December, January 29). Differential Fault Analysis on Midori. Proceedings of the Information and Communications Security (ICICS 2016), Singapore.","DOI":"10.1007\/978-3-319-50011-9_24"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Korkikian, R., Pelissier, S., and Naccache, D. (2014, January 23). Blind Fault Attack Against SPN Ciphers. Proceedings of the 2014 Workshop on Fault Diagnosis and Tolerance in Cryptography, Busan, South Korea.","DOI":"10.1109\/FDTC.2014.19"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"896","DOI":"10.1080\/18756891.2012.733223","article-title":"Single byte differential fault analysis on the LED lightweight cipher in the wireless sensor network","volume":"5","author":"Li","year":"2012","journal-title":"Int. J. Comput. Intell. Syst."},{"key":"ref_18","unstructured":"Vasquez, J.D.C.G., Borges, F., Portugal, R., and Lara, P. (2015, January 13). An Efficient One-Bit Model for Differential Fault Analysis on SIMON Family. Proceedings of the Workshop on Fault Diagnosis Tolerance Cryptography (FDTC), St. Malo, France."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Saha, D., Mukhopadhyay, D., and Chowdhury, D.R. (2009, November 30). A Diagonal Fault Attack on the Advanced Encryption Standard. Available online: https:\/\/eprint.iacr.org\/2009\/581.pdf.","DOI":"10.1109\/ECCTD.2009.5275006"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"150","DOI":"10.46586\/tches.v2018.i3.150-172","article-title":"Persistent fault analysis on block ciphers","volume":"3","author":"Zhang","year":"2018","journal-title":"IACR Trans. Cryptol. Hardw. Embed. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Mendel, F., Rechberger, C., Schl\u00e4ffer, M., and Thomsen, S.S. (2009, January 22\u201325). The Rebound Attack: Cryptanalysis of Reduced Whirlpool and Gr\u00f8stl. Proceedings of the Fast Software Encryption (FSE), Leuven, Belgium.","DOI":"10.1007\/978-3-642-03317-9_16"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Moro, N., Dehbaoui, A., Heydemann, K., Robisson, B., and Encrenaz, E. (2013, January 20). Electromagnetic Fault Injection: Towards a Fault Model on a 32-bit Microcontroller. Proceedings of the Workshop on Fault Diagnosis Tolerance Cryptography (FDTC 2013), Santa Barbara, CA, USA.","DOI":"10.1109\/FDTC.2013.9"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Gandolfi, K., Mourtel, C., and Olivier, F. (2001, January 14\u201316). Electromagnetic analysis: Concrete results. Proceedings of the International Workshop on Cryptographic Hardware and Embedded Systems, Paris, France.","DOI":"10.1007\/3-540-44709-1_21"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Agoyan, M., Dutertre, J.M., Mirbaha, A.P., Naccache, D., Ribotta, A.L., and Tria, A. (2010, January 8\u201310). Single-Bit DFA Using Multiple-Byte Laser Fault Injection. Proceedings of the 2010 IEEE International Conference on Technologies for Homeland Security (HST), Waltham, MA, USA.","DOI":"10.1109\/THS.2010.5655079"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Banik, S., Bogdanov, A., Isobe, T., Shibutani, K., Hiwatari, H., Akishita, T., and Regazzoni, F. (December, January 29). Midori: A Block Cipher for Low Energy. Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2015, Auckland, New Zealand.","DOI":"10.1007\/978-3-662-48800-3_17"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Nozaki, Y., and Yoshikawa, M. (2017, January 18\u201320). Statistical Fault Analysis for a Lightweight Cipher Midori. Proceedings of the International Conference on Information and Automation (ICIA 2017), Macau, China.","DOI":"10.1109\/ICInfA.2017.8078912"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"1383","DOI":"10.1007\/s00145-018-9285-0","article-title":"Nonlinear invariant attack: Practical attack on full scream, iscream, and midori64","volume":"32","author":"Todo","year":"2019","journal-title":"J. Crypt."},{"key":"ref_28","first-page":"216","article-title":"DEAL-A 128-bit cipher","volume":"258","author":"Knudsen","year":"1998","journal-title":"Complexity"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Biham, E., and Shamir, A. (1997, January 17\u201321). Differential Fault Analysis of Secret Key Cryptosystems. Proceedings of the 17th Annual International Cryptology Conference Advances in Cryptology (CRYPTO 1997), Santa Barbara, CA, USA.","DOI":"10.1007\/BFb0052259"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Jovanovic, P., Kreuzer, M., and Polian, I. (2012, July 17). An Algebraic Fault Attack on the LED Block Cipher. Available online: https:\/\/eprint.iacr.org\/2012\/400.pdf.","DOI":"10.1007\/978-3-642-29912-4_10"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11427-019-9817-6","article-title":"Ciphertext-only fault analysis on the Midori lightweight cryptosystem","volume":"63","author":"Li","year":"2020","journal-title":"Sci. China Inf. Sci."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"210","DOI":"10.1007\/s11432-016-0071-7","article-title":"Improving DFA attacks on AES with unknown and random faults","volume":"60","author":"Liao","year":"2017","journal-title":"Sci. China Inf. Sci."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1109\/TIFS.2011.2174984","article-title":"Information-theoretic approach to optimal differential fault analysis","volume":"7","author":"Sakiyama","year":"2012","journal-title":"IEEE Trans. Inf. Forensics Secur."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/7\/1976\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:14:21Z","timestamp":1760174061000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/7\/1976"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,4,1]]},"references-count":33,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2020,4]]}},"alternative-id":["s20071976"],"URL":"https:\/\/doi.org\/10.3390\/s20071976","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2020,4,1]]}}}