Differential fault analysis on the SMS4 cipher by inducing faults to the key schedule

On the basis of the byte-oriented fault model and the differential analysis,a differential fault analysis on the SMS4 cipher by inducing faults in its key schedule was proposed.Mathematical analysis and simulating experiment show that the attack could recover its 128-bit secret key by introducing only eight faulty ciphertexts.Simultaneously,a method of distinguishing effective faults was presented to increase the efficiency of fault injection and decrease the num-ber of faulty ciphertexts.Thus,experiment results are beneficial to the analysis of other iterated block ciphers.