Tweakable Permutation-Based Luby-Rackoff Constructions
Bishwajit Chakraborty, Abishanka Saha
Abstract
Liskov, Rivest, and Wagner, in their seminal work, formulated tweakable blockciphers and proposed two blockcipher-based design paradigms, LRW1 and LRW2, where the basic design strategy is to xor the masked tweak to the input and output of a blockcipher. The 2-round cascaded LRW2 and 4-round cascaded LRW1 have been proven to be secure up to queries, but -bit optimal security still remains elusive for these designs. In their paper, Liskov also posed an open challenge of embedding the tweak directly in the blockcipher, and to address this, Goldenberg et al. introduced the tweakable Luby-Rackoff (LR) constructions. They showed that if the internal primitives are random functions, then for tweaks with blocks, the construction needs rounds to be optimally -bit CPA secure and rounds to be optimally -bit CCA secure, where respectively and rounds were required to process the tweaks. Since blockciphers can be designed much more efficiently than pseudorandom functions, in many practical applications the internal primitives of LR ciphers are instantiated as blockciphers, which however would lead to a birthday-bound factor, which is not ideal for say lightweight cryptography.
This paper addresses the following two key questions affirmatively: (1) Can Goldenberg et al.'s results be extended to LR constructions with random permutations as internal primitives without compromising the optimal -bit security? (2) Can the number of rounds required for handling long tweaks be reduced?
We formally define TLR-compatible functions, for processing the tweak, which when composed with 4-rounds and 5-rounds of LR construction with random permutations as internal primitives gives us respectively -bit CPA and CCA secure tweakable permutations. For the security analysis, we proved general Mirror Theory result for three permutations. We also propose instantiating TLR-compatible functions with one round LR where a permutation (resp, two AXU hash functions) is used to mask single-block tweaks (resp., variable-length tweaks), thus proposing the -bit CPA (resp., CCA) secure tweakable permutation candidates, and (resp., and ), using (resp., ) LR rounds, which is a significant reduction from the tweak-length-dependent results of Goldenberg et al.
We further extend the implications of our analysis of permutation-based LR as follows: (1) We show -bit CPA (resp., CCA) security of -rounds (resp. -rounds) permutation-based LR construction, which is quite an improvement over the existing -bit security proved by Guo et al. (2) We propose a new design paradigm, , for -bit secure MACs, that involves hashing the message, then passing the diblock tag through four rounds of permutation-based LR and then truncating the left block.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Tight Security of TNT and Beyond - Attacks, Proofs and Possibilities for the Cascaded LRW ParadigmAshwin Jha, Mustafa Khairallah, Mridul Nandi, Abishanka SahaEUROCRYPT 2024 · 7 citations
- Post-quantum Security of Tweakable Even-Mansour, and ApplicationsGorjan Alagic, Chen Bai, Jonathan Katz, Christian Majenz et al.EUROCRYPT 2024 · 10 citations
- How to Recover the Full Plaintext of XCBPeng Wang, Shuping Mao, Ruozhou Xu, Jiwu Jing et al.CRYPTO 2025 · 3 citations
- Impossibility of Indifferentiable Iterated Blockciphers from 3 or Less Primitive CallsChun Guo, Lei Wang, Dongdai LinEUROCRYPT 2023 · 5 citations
- Lightweight Authenticated Encryption Mode Suitable for Threshold ImplementationYusuke Naito, Yu Sasaki, Takeshi SugawaraEUROCRYPT 2020 · 33 citations
