Differential Fault Analysis on Piccolo
Guang Hui Zhao · Chinese Journal of Computers · 2012
Piccolo was proposed at CHES 2011 as a lightweight block cipher with block size 64-bit.The key size of Piccolo is 80-bit/128-bit,and the corresponding round number is 25/31.Piccolo adopts a variant of generalized Feistel structure,and its round transformation consists of the round function S-P-S and the round permutation PR.The designers show that Piccolo is resistant against most classical attacks,such as differential and linear cryptanalysis.This paper presents a first differential fault analysis on Piccolo-80 based on the random nibble-oriented fault model by treating the S-P-S function as a Super Sbox.Both the theoretical analysis and the experimental result demonstrate that the key space can be reduced from 80-bit to about 22-bit by injecting a fault at the first and third register in the 24th input respectively.This indicates that cryptographic devices supporting Piccolo should be carefully protected.