Layout Graphs, Random Walks and the t-Wise Independence of SPN Block Ciphers
Tianren Liu, Angelos Pelecanos, Stefano Tessaro, Vinod Vaikuntanathan
Abstract
We continue the study of -wise independence of substitution-permutation networks (SPNs) initiated by the recent work of Liu, Tessaro, and Vaikuntanathan (CRYPTO 2021). Our key technical result shows that when the S-boxes are randomly and independently chosen and kept secret, an -round SPN with input length is -close to -wise independent within rounds for any almost as large as . Here, is the input length of the S-box and we assume that the underlying mixing achieves maximum branch number. We also analyze the special case of AES parameters (with random S-boxes), and show it is -close to pairwise independent in rounds. Central to our result is the analysis of a random walk on what we call the layout graph, a combinatorial abstraction that captures equality and inequality constraints among multiple SPN evaluations. We use our technical result to show concrete security bounds for SPNs with actual block cipher parameters and small-input -boxes. (This is in contrast to the large body of results on ideal-model analyses of SPNs.) For example, for the censored-AES block cipher, namely AES with most of the mixing layers removed, we show that 192 rounds suffice to attain -closeness to pairwise independence. The prior such result for AES (Liu, Tessaro and Vaikuntanathan, CRYPTO 2021) required more than 9000 rounds.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 84e2ba0f-cfb3-48cd-8b1b-5651acf64470Cited by top-tier papers1
Ask how each one uses itRelated papers
- The t-wise Independence of Substitution-Permutation NetworksTianren Liu, Stefano Tessaro, Vinod VaikuntanathanCRYPTO 2021 · 17 citations
- Pairwise Independence of AES-Like Block CiphersTim Beyne, Gregor Leander, Immo SchüttEUROCRYPT 2026 · 1 citation
- How Fast Does the Inverse Walk Approximate a Random Permutation?Vishesh Jain, Tianren Liu, Clayton Mizgerd, Angelos Pelecanos et al.CRYPTO 2026 · 1 citation
- New Techniques for Analyzing Differentials with Application to AESItai DinurEUROCRYPT 2026
- When Simple Permutations Mix Poorly - Limited Independence does not Imply PseudorandomnessJesko Dujmovic, Angelos Pelecanos, Stefano TessaroEUROCRYPT 2026
