Paper 2026/1833

On the Fault Injection Security of White-box Ciphers

Md Alamgir Alam, Institute for Advancing Intelligence, TCG CREST, Kolkata, India, Academy of Scientific and Innovative Research (AcSIR), India
Avik Chakraborti, Institute for Advancing Intelligence, TCG CREST, Kolkata, India, Academy of Scientific and Innovative Research (AcSIR), India
Takanori Isobe, Osaka University, Osaka, Japan
Sajani Kundu, Institute for Advancing Intelligence, TCG CREST, Kolkata, India, Ramakrishna Mission Vivekananda Educational and Research Institute, India
Sayandeep Saha, Indian Institute of Technology Bombay, Mumbai, India
Abstract

White-box security settings assume an extremely powerful adversary having full visibility and control of the software implementation and internal computations. Leakage-based attacks extract secret information via a local passive attacker (e.g., malware) and transmit it to a remote server. However, an active adversary, who can perform fault injections in a white box setting, has received limited attention, especially in the symmetric-key setting. In this paper, we initiate a formal study of active data-only adversaries in the white-box setting. Such adversaries preserve the control flow of the implementation but corrupt a bounded number of key-embedded lookup-table entries, enabling precise and repeatable manipulation of table values. Unlike leakage-based attacks, which are constrained by the bandwidth and existence of firewalls, such fault attacks can operate entirely locally. We focus on a data-only tampering adversary that preserves the control flow of the white-box implementation, but corrupts a bounded number of key-embedded lookup-table entries. Even under this stealth-preserving restriction, the adversary can cryptographically weaken the implementation and make faulty ciphertexts significantly easier to decrypt. We formalize such an active adversary by defining a new security notion and studying its impact on contemporary table-based white-box implementations. Our analyses reveal a structural disparity between two major design paradigms: Feistel-based white-box ciphers appear significantly more vulnerable to fault injection than SPN-based designs. Finally, we propose a software-based fault detection mechanism that detects fault injections with high probability, strengthening resilience. We provide detailed analysis of the SPN-based cipher WEM (the same analyses also work for other SPN-based ciphers like SPNbox), and two Feistel-based ciphers SPACE and Galaxy. Our analyses reveal that SPACE and Galaxy are significantly more vulnerable than WEM, under our fault-based security setting. Precisely, we show that WEM achieves high security under all the adversarial models, whereas SPACE and Galaxy instances can be attacked with a very high message recovery probability of $2^{-8}$, when the adversary can choose the fault positions and the values and corrupts up to one fourth of the implementation table entries.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
white-box cryptographyfault injectiontable-based constructionsFeistel networksSPN.
Contact author(s)
md alamgir alam 119 @ tcgcrest org
avik chakraborti @ tcgcrest org
takanori isobe @ ist osaka-u ac jp
sajani kundu 89 @ tcgcrest org
sayandeepsaha @ cse iitb ac in
History
2026-08-30: approved
2026-08-29: received
See all versions
Short URL
https://ia.cr/2026/1833
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/1833,
      author = {Md Alamgir Alam and Avik Chakraborti and Takanori Isobe and Sajani Kundu and Sayandeep Saha},
      title = {On the Fault Injection Security of White-box Ciphers},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1833},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1833}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.