Lune

CRYPTO2021Top-tier venue

Linear Cryptanalysis of FF3-1 and FEA

Tim Beyne

2021Year
11Citations

Abstract

Improved attacks on generic small-domain Feistel ciphers with alternating round tweaks are obtained using linear cryptanalysis. This results in practical distinguishing and message-recovery attacks on the United States format-preserving encryption standard FF3-1 and the South-Korean standards FEA-1 and FEA-2. The data-complexity of the proposed attacks on FF3-1 and FEA-1 is O(Nr/2−1.5)O(N^{r/2 - 1.5}), where N2N^2 is the domain size and rr is the number of rounds. For example, FF3-1 with N=103N = 10^3 can be distinguished from an ideal tweakable block cipher with advantage ≥1/10\ge 1/10 using 2232^{23} encryption queries. Recovering the left half of a message with similar advantage requires 2242^{24} data. The analysis of FF3-1 serves as an interesting real-world application of (generalized) linear cryptanalysis over the group Z/NZ\mathbb{Z}/N\mathbb{Z}.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 52710d53-9d4e-419e-8811-3df6d887456d

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines