Linear Cryptanalysis of FF3-1 and FEA
Tim Beyne
Abstract
Improved attacks on generic small-domain Feistel ciphers with alternating round tweaks are obtained using linear cryptanalysis. This results in practical distinguishing and message-recovery attacks on the United States format-preserving encryption standard FF3-1 and the South-Korean standards FEA-1 and FEA-2. The data-complexity of the proposed attacks on FF3-1 and FEA-1 is , where is the domain size and is the number of rounds. For example, FF3-1 with can be distinguished from an ideal tweakable block cipher with advantage using encryption queries. Recovering the left half of a message with similar advantage requires data. The analysis of FF3-1 serves as an interesting real-world application of (generalized) linear cryptanalysis over the group .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 52710d53-9d4e-419e-8811-3df6d887456dRelated papers
- Message-Recovery Attacks on Feistel-Based Format Preserving EncryptionMihir Bellare, Viet Tung Hoang, Stefano TessaroCCS 2016 · 38 citations
- Three Third Generation Attacks on the Format Preserving Encryption Scheme FF3Ohad Amon, Orr Dunkelman, Nathan Keller, Eyal Ronen et al.EUROCRYPT 2021 · 8 citations
- Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type DesignsTingting Guo, Peng Wang, Jiwu Jing, Shuping Mao et al.CRYPTO 2026
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos et al.EUROCRYPT 2024 · 4 citations
- Feistel-Like Structures Revisited: Classification and CryptanalysisBing Sun, Zejun Xiang, Zhengyi Dai, Guoqiang Liu et al.CRYPTO 2024 · 5 citations
