Message-Recovery Attacks on Feistel-Based Format Preserving Encryption
Mihir Bellare, Viet Tung Hoang, Stefano Tessaro
Abstract
We give attacks on Feistel-based format-preserving encryption (FPE) schemes that succeed in message recovery (not merely distinguishing scheme outputs from random) when the message space is small. For -bit messages, the attacks fully recover the target message using examples for the FF3 NIST standard and examples for the FF1 NIST standard. The examples include only three messages per tweak, which is what makes the attacks non-trivial even though the total number of examples exceeds the size of the domain. The attacks are rigorously analyzed in a new definitional framework of message-recovery security. The attacks are easily put out of reach by increasing the number of Feistel rounds in the standards.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Linear Cryptanalysis of FF3-1 and FEATim BeyneCRYPTO 2021 · 11 citations
- Three Third Generation Attacks on the Format Preserving Encryption Scheme FF3Ohad Amon, Orr Dunkelman, Nathan Keller, Eyal Ronen et al.EUROCRYPT 2021 · 8 citations
- Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type DesignsTingting Guo, Peng Wang, Jiwu Jing, Shuping Mao et al.CRYPTO 2026
- Feistel-Like Structures Revisited: Classification and CryptanalysisBing Sun, Zejun Xiang, Zhengyi Dai, Guoqiang Liu et al.CRYPTO 2024 · 5 citations
- Efficient Key Recovery for All HFE Signature VariantsChengdong Tao, Albrecht Petzoldt, Jintai DingCRYPTO 2021 · 41 citations
