
@Article{cmc.2026.087189,
AUTHOR = {Yanjun Li, Yiping Lin, Yuting Ni, Lixian Zhang, Shanshan Huo},
TITLE = {Security Analysis of a Modulo-2<b><sup>16</sup></b> Implementation Variant of the MBRISI Lightweight ARX Block Cipher: Weak Keys, Deterministic Differentials, and Equivalent Keys},
JOURNAL = {Computers, Materials \& Continua},
VOLUME = {},
YEAR = {},
NUMBER = {},
PAGES = {{pages}},
URL = {http://www.techscience.com/cmc/online/detail/28244},
ISSN = {1546-2226},
ABSTRACT = {This paper presents an exact security evaluation of a closed modulo-<math id="mml-ieqn-1"><msup><mn>2</mn><mrow><mn>16</mn></mrow></msup></math> implementation variant of the lightweight Add–Rotate–XOR (ARX) block cipher named MBRISI. We first resolve an arithmetic ambiguity in the original specification: modulo-65,537 addition on 16-bit words may produce the unrepresentable value 65,536, while representing its outputs by 16-bit overflow is non-injective. We construct distinct plaintext pairs that merge after the first round and consequently produce identical ciphertexts. In contrast, modulo-<math id="mml-ieqn-2"><msup><mn>2</mn><mrow><mn>16</mn></mrow></msup></math> addition is closed and bijective over the 16-bit word space; therefore, all subsequent weak-key and equivalent-key results apply exclusively to this implementation variant. We prove that addition by a fixed round key is affine over <math id="mml-ieqn-3"><mrow><mi mathvariant="normal">G</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><mn>2</mn><msup><mo stretchy="false">)</mo><mrow><mn>16</mn></mrow></msup></math> if and only if the key belongs to <math id="mml-ieqn-4"><mo fence="false" stretchy="false">{</mo><mrow><mn>0</mn><mi mathvariant="normal">x</mi><mn>0000</mn></mrow><mo>,</mo><mrow><mn>0</mn><mi mathvariant="normal">x</mi><mn>4000</mn></mrow><mo>,</mo><mrow><mn>0</mn><mi mathvariant="normal">x</mi><mn>8000</mn></mrow><mo>,</mo><mrow><mn>0</mn><mi mathvariant="normal">x</mi><mi mathvariant="normal">C</mi><mn>000</mn></mrow><mo fence="false" stretchy="false">}</mo></math>, in which case every XOR difference propagates deterministically. Because this set is closed under the MBRISI round-key recurrence, weak initial subkeys make the complete ten-round encryption mapping affine over <math id="mml-ieqn-5"><mrow><mi mathvariant="normal">G</mi><mi mathvariant="normal">F</mi></mrow><mo stretchy="false">(</mo><mn>2</mn><msup><mo stretchy="false">)</mo><mrow><mn>32</mn></mrow></msup></math>. By modeling the rotation–XOR preprocessing as linear maps, we show that their images equal the even-parity subspace, their kernels have dimension one, and every image element has exactly two complementary preimages. These properties reduce exact weak-key counting and structural identification from <math id="mml-ieqn-6"><msup><mn>2</mn><mrow><mn>32</mn></mrow></msup></math> half-key-pair tests to <math id="mml-ieqn-7"><mrow><mrow><mi>},
DOI = {10.32604/cmc.2026.087189}
}



