Security Analysis of a Modulo-216 Implementation Variant of the MBRISI Lightweight ARX Block Cipher: Weak Keys, Deterministic Differentials, and Equivalent Keys
Yanjun Li, Yiping Lin, Yuting Ni, Lixian Zhang, Shanshan Huo · Computers, materials & continua/Computers, materials & continua (Print) · 2026
This paper presents an exact security evaluation of a closed modulo-2 16 implementation variant of the lightweight Add-Rotate-XOR (ARX) block cipher named MBRISI.We first resolve an arithmetic ambiguity in the original specification: modulo-65,537 addition on 16-bit words may produce the unrepresentable value 65,536, while representing its outputs by 16-bit overflow is non-injective.We construct distinct plaintext pairs that merge after the first round and consequently produce identical ciphertexts.In contrast, modulo-2 16 addition is closed and bijective over the 16-bit word space; therefore, all subsequent weak-key and equivalent-key results apply exclusively to this implementation variant.We prove that addition by a fixed round key is affine over GF(2) 16 if and only if the key belongs to {0x0000, 0x4000, 0x8000, 0xC000}, in which case every XOR difference propagates deterministically.Because this set is closed under the MBRISI round-key recurrence, weak initial subkeys make the complete ten-round encryption mapping affine over GF(2) 32 .By modeling the rotation-XOR preprocessing as linear maps, we show that their images equal the even-parity subspace, their kernels have dimension one, and every image element has exactly two complementary preimages.These properties reduce exact weak-key counting and structural identification from 2 32 half-key-pair tests to O(2 15 ) word operations and yield exactly 2 36 universal weak master keys, representing 2 -28 of the key space.Such keys induce deterministic full-round differentials, while large equivalent-key fibers produce identical round-key sequences and encryption mappings.Beyond MBRISI, the analysis yields a reusable audit framework for clarifying arithmetic domains, characterizing exceptional addition constants and carry behavior, testing key-schedule invariants, and guiding the secure design and evaluation of lightweight ARX ciphers.