Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.087189
Special Issues
Table of Content

Open Access

ARTICLE

Security Analysis of a Modulo-216 Implementation Variant of the MBRISI Lightweight ARX Block Cipher: Weak Keys, Deterministic Differentials, and Equivalent Keys

Yanjun Li1,2, Yiping Lin2,*, Yuting Ni2, Lixian Zhang2, Shanshan Huo1
1 Information Industry Information Security Evaluation Center, The 15th Research Institute of China Electronics Technology Group Corporation, Beijing, China
2 Beijing Electronic Science and Technology Institute, Beijing, China
* Corresponding Author: Yiping Lin. Email: email

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.087189

Received 11 June 2026; Accepted 14 August 2026; Published online 10 September 2026

Abstract

This paper presents an exact security evaluation of a closed modulo-216 implementation variant of the lightweight Add–Rotate–XOR (ARX) block cipher named MBRISI. We first resolve an arithmetic ambiguity in the original specification: modulo-65,537 addition on 16-bit words may produce the unrepresentable value 65,536, while representing its outputs by 16-bit overflow is non-injective. We construct distinct plaintext pairs that merge after the first round and consequently produce identical ciphertexts. In contrast, modulo-216 addition is closed and bijective over the 16-bit word space; therefore, all subsequent weak-key and equivalent-key results apply exclusively to this implementation variant. We prove that addition by a fixed round key is affine over GF(2)16 if and only if the key belongs to {0x0000,0x4000,0x8000,0xC000}, in which case every XOR difference propagates deterministically. Because this set is closed under the MBRISI round-key recurrence, weak initial subkeys make the complete ten-round encryption mapping affine over GF(2)32. By modeling the rotation–XOR preprocessing as linear maps, we show that their images equal the even-parity subspace, their kernels have dimension one, and every image element has exactly two complementary preimages. These properties reduce exact weak-key counting and structural identification from 232 half-key-pair tests to

Keywords

Lightweight block cipher; ARX cipher; IoT security; differential cryptanalysis; weak key; deterministic differential; equivalent key; key schedule

Share Link