Linear Cryptanalysis of FF3-1 and FEA
Tim Beyne
摘要
Improved attacks on generic small-domain Feistel ciphers with alternating round tweaks are obtained using linear cryptanalysis. This results in practical distinguishing and message-recovery attacks on the United States format-preserving encryption standard FF3-1 and the South-Korean standards FEA-1 and FEA-2. The data-complexity of the proposed attacks on FF3-1 and FEA-1 is , where is the domain size and is the number of rounds. For example, FF3-1 with can be distinguished from an ideal tweakable block cipher with advantage using encryption queries. Recovering the left half of a message with similar advantage requires data. The analysis of FF3-1 serves as an interesting real-world application of (generalized) linear cryptanalysis over the group .
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Message-Recovery Attacks on Feistel-Based Format Preserving EncryptionMihir Bellare, Viet Tung Hoang, Stefano TessaroCCS 2016 · 被引用 38 次
- Three Third Generation Attacks on the Format Preserving Encryption Scheme FF3Ohad Amon, Orr Dunkelman, Nathan Keller, Eyal Ronen 等EUROCRYPT 2021 · 被引用 8 次
- Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type DesignsTingting Guo, Peng Wang, Jiwu Jing, Shuping Mao 等CRYPTO 2026
- Generalized Feistel Ciphers for Efficient Prime Field MaskingLorenzo Grassi, Loïc Masure, Pierrick Méaux, Thorben Moos 等EUROCRYPT 2024 · 被引用 4 次
- Feistel-Like Structures Revisited: Classification and CryptanalysisBing Sun, Zejun Xiang, Zhengyi Dai, Guoqiang Liu 等CRYPTO 2024 · 被引用 5 次
