Requirements for Feistel-based Lightweight Block Cipher S-boxes to be Resilient to Boomerang Attacks

David Carcano Ventura, Lil María Rodríguez-Henríquez, Saúl E. Pomares Hernández · 2023

The S-box component is crucial in the design of Feistel-based Lightweight Block Ciphers (LBCs) as it serves as the main non-linear component, providing them with confusion. S-box resistance to cryptographic attacks differs among solutions, and it can be assessed by measuring its cryptographic properties, such as Differential Uniformity (DU), Feistel Boomerang Uniformity (FBU), and Feistel Boomerang Difference Uniformity (FBDU). The DU is directly related to the resistance against Differential attacks. Even though an S-box achieves its optimal value in this property, it may still be susceptible to the Boomerang attacks, which are an extension of the Differential attacks. Hence, the designer must consider that reaching low values of the DU, FBU, and FBDU properties is a requirement of a new S-box to be resilience to Differential and Boomerang attacks. In this paper, we introduce an analysis of the S-boxes used in Feistel-based LBCs, which reveals that most of the current S-boxes are susceptible to Boomerang attacks. Therefore, new designs of this component that include the requirements established in this analysis are necessary.

Read the paper · More papers on PaperTik