Paper 2026/1833
On the Fault Injection Security of White-box Ciphers
Abstract
White-box security settings assume an extremely powerful adversary having full visibility and control of the software implementation and internal computations. Leakage-based attacks extract secret information via a local passive attacker (e.g., malware) and transmit it to a remote server. However, an active adversary, who can perform fault injections in a white box setting, has received limited attention, especially in the symmetric-key setting. In this paper, we initiate a formal study of active data-only adversaries in the white-box setting. Such adversaries preserve the control flow of the implementation but corrupt a bounded number of key-embedded lookup-table entries, enabling precise and repeatable manipulation of table values. Unlike leakage-based attacks, which are constrained by the bandwidth and existence of firewalls, such fault attacks can operate entirely locally. We focus on a data-only tampering adversary that preserves the control flow of the white-box implementation, but corrupts a bounded number of key-embedded lookup-table entries. Even under this stealth-preserving restriction, the adversary can cryptographically weaken the implementation and make faulty ciphertexts significantly easier to decrypt. We formalize such an active adversary by defining a new security notion and studying its impact on contemporary table-based white-box implementations. Our analyses reveal a structural disparity between two major design paradigms: Feistel-based white-box ciphers appear significantly more vulnerable to fault injection than SPN-based designs. Finally, we propose a software-based fault detection mechanism that detects fault injections with high probability, strengthening resilience. We provide detailed analysis of the SPN-based cipher WEM (the same analyses also work for other SPN-based ciphers like SPNbox), and two Feistel-based ciphers SPACE and Galaxy. Our analyses reveal that SPACE and Galaxy are significantly more vulnerable than WEM, under our fault-based security setting. Precisely, we show that WEM achieves high security under all the adversarial models, whereas SPACE and Galaxy instances can be attacked with a very high message recovery probability of $2^{-8}$, when the adversary can choose the fault positions and the values and corrupts up to one fourth of the implementation table entries.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- white-box cryptographyfault injectiontable-based constructionsFeistel networksSPN.
- Contact author(s)
-
md alamgir alam 119 @ tcgcrest org
avik chakraborti @ tcgcrest org
takanori isobe @ ist osaka-u ac jp
sajani kundu 89 @ tcgcrest org
sayandeepsaha @ cse iitb ac in - History
- 2026-08-30: approved
- 2026-08-29: received
- See all versions
- Short URL
- https://ia.cr/2026/1833
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/1833,
author = {Md Alamgir Alam and Avik Chakraborti and Takanori Isobe and Sajani Kundu and Sayandeep Saha},
title = {On the Fault Injection Security of White-box Ciphers},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1833},
year = {2026},
url = {https://eprint.iacr.org/2026/1833}
}