Lune

CCS2016Top-tier venue

Message-Recovery Attacks on Feistel-Based Format Preserving Encryption

Mihir Bellare, Viet Tung Hoang, Stefano Tessaro

2016Year
38Citations
1Top-tier citations

Abstract

We give attacks on Feistel-based format-preserving encryption (FPE) schemes that succeed in message recovery (not merely distinguishing scheme outputs from random) when the message space is small. For 44-bit messages, the attacks fully recover the target message using 2212^{21} examples for the FF3 NIST standard and 2252^{25} examples for the FF1 NIST standard. The examples include only three messages per tweak, which is what makes the attacks non-trivial even though the total number of examples exceeds the size of the domain. The attacks are rigorously analyzed in a new definitional framework of message-recovery security. The attacks are easily put out of reach by increasing the number of Feistel rounds in the standards.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers1

Ask how each one uses it

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines