International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

MIFA:

An MILP-based Framework for Improving Differential Fault Attacks


Hanbeom Shin
Korea University, South Korea

Insung Kim
Korea University, South Korea

Sunyeop Kim
Korea University, South Korea; Nanyang Technological University, Singapore

Byoungjin Seok
Hansung University, South Korea

Deukjo Hong
Jeonbuk National University, South Korea

Jaechul Sung
University of Seoul, South Korea

Seokhie Hong
SmartM2M, South Korea

Sangjin Lee
Korea University, South Korea

Dongjae Lee
Kangwon National University, South Korea


Keywords: MIFA, Differential Fault Attack, MILP, DEFAULT, BAKSHEESH


Abstract

At ASIACRYPT 2021, Baksi et al. introduced DEFAULT, a block cipher designed to algorithmically resist Differential Fault Attack (DFA), claiming 64-bit DFA security regardless of the number of injected faults. At EUROCRYPT 2022, Nageler et al. demonstrated that DEFAULT’s claimed DFA resistance can be broken by applying an information-combining technique. More recently, at ASIACRYPT 2024, Jana et al. improved DFA by searching for differential trails with a single solution. They showed that, for DEFAULT with a simple key schedule, injecting five faults at the fifth-to-last round reduces the key space to one, and for BAKSHEESH, injecting twelve faults at the third-to-last round achieves the same result. In this paper, we propose a new DFA framework that utilizes a Mixed-Integer Linear Programming (MILP) solver. This framework makes it possible to attack deeper rounds than previously achieved, reducing the number of fault injections required for key recovery. Furthermore, we present a method to determine the most efficient fault injection bit positions by systematically analyzing the input differences from all possible single bit-flip faults, thereby further reducing the required number of faults. This systematic analysis has the significant advantage of allowing us to theoretically calculate the required number of faults. Applying our framework, for DEFAULT, injecting three faults at the sixth-to-last round and two faults at the seventh- and eighth-to-last rounds reduces the key space to one.

Publication

IACR Transactions on Cryptographic Hardware and Embedded Systems, Volume 2026, Issue 3

Paper

Artifact

Artifact number
tches/2026/a38

Artifact published
September 21, 2026

Badge
✅ IACR CHES Artifacts Functional

README

ZIP (18143354 Bytes)  

View on Github

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Hanbeom Shin, Insung Kim, Sunyeop Kim, Byoungjin Seok, Deukjo Hong, Jaechul Sung, Seokhie Hong, Sangjin Lee, Dongjae Lee. (2026). MIFA: An MILP-based Framework for Improving Differential Fault Attacks. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2026(3), 465–488. https://doi.org/10.46586/tches.v2026.i3.465-488. Artifact at https://artifacts.iacr.org/tches/2026/a38.