Differential Fault Attacks of AEGIS Algorithm Based on Random Bits
Zhongya Zhang, Geng Chen, Yuan Gao, Zhiyong Zhang · IEEE Internet of Things Journal · 2025
AEGIS is a lightweight cipher for resource constrained environments such as the Internet of Things (IoT), which is one of the seven algorithms that ultimately won the CAESAR competition, and has become a focus of cryptographic research. Differential fault attack is a method to recover important secret data by researching the difference in state before and after injecting a fault, which is one of the most serious threats to lightweight cryptographic algorithms. This paper propose differential fault attacks on AEGIS based on the random bit fault model, which theoretically respectively requires only 141, 176, and 246 random bit faults to fully recover the intermediate state of AEGIS-128, AEGIS-256, and AEGIS-L, which are far superior to the known results in terms of the number of faults, computational complexity, and difficulty of models. The attack method on AEGIS contributes to assessing the security of IoT devices and systems, while also guiding the design of IoT security defense strategies. The approach proactively detects vulnerabilities in lightweight cryptographic algorithms implemented on resource-constrained devices such as sensors and smart home chips, thus driving enhancements in algorithms and hardware, and has great significance for the security of IoT platforms.