Abstract: Round addition differential fault analysis using
operation skipping for lightweight block ciphers with on-the-fly key
scheduling is presented. For 64-bit KLEIN, it is shown that only a pair
of correct and faulty ciphertexts can be used to derive the secret master
key. For PRESENT, one correct ciphertext and two faulty ciphertexts
are required to reconstruct the secret key. Furthermore, secret key
extraction is demonstrated for the LBlock Feistel-type lightweight
block cipher.