Revisiting Key-alternating Feistel Ciphers for Shorter Keys and Multi-user Security

Revisiting Key-alternating Feistel Ciphers for Shorter Keys and Multi-user Security
复制标题

DOI:
10.1007/978-3-030-03326-2_8
复制
发表时间:
2018-12
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Chun Guo;Lei Wang
Chun Guo;Lei Wang
中科院分区:
其他
文献类型:
--
作者:
Chun Guo;Lei Wang

文献摘要

被引文献

相似文献

密钥交替Feistel(KAF)密码,也称为Feistel-2模型,是指Feistel网络具有轮函数的形式,其中是(秘密)轮密钥,是一个泛随机函数。该模型大致上描述了许多著名的Feistel密码的结构,最突出的例子是DES。现有的关于KAF的可证明安全性结果假设了独立的轮密钥和轮函数(ASIACRYPT 2004 & FSE 2014)。在本文中,我们研究如何在更简单和更现实的假设下实现安全性:对于生日型安全,我们考虑了4-roundKAF,研究了导出4个轮密钥的最小条件,并证明了当使用充分导出的密钥和相同的轮函数时,4轮KAF最多保护查询,对于生日之后的安全性,我们重点关注6轮KAF。我们证明了当相邻的轮密钥是独立的,并且使用独立的轮函数时,6轮KAF是安全的。据我们所知,这是KAF在不假设完全独立的轮密钥的情况下的第一个超越生日安全性结果,我们的结果在多用户设置下也成立,构成了Feistel密码的第一个非平凡多用户可证明安全性结果。最后,我们展示了我们的研究结果的应用程序设计的关键时刻表和实例化键控海绵建设。
Key-Alternating Feistel (KAF) ciphers, a.k.a. Feistel-2 models, refer to Feistel networks with round functions of the form, whereis the (secret) round-key andis apublicrandom function. This model roughly captures the structures of many famous Feistel ciphers, and the most prominent instance is DES.Existing provable security results onKAFassumed independent round-keys and round functions (ASIACRYPT 2004 & FSE 2014). In this paper, we investigate how to achieve security under simpler and more realistic assumptions: with round-keys derived from a short main-key, and hopefully with identical round functions.For birthday-type security, we consider 4-roundKAF, investigate the minimal conditions on the way to derive the four round-keys, and prove that when such adequately derived keys and the same round function are used, the 4-roundKAFis secure up toqueries.For beyond-birthday security, we focus on 6-roundKAF. We prove that when the adjacent round-keys are independent, and independent round-functions are used, the 6 roundKAFis secure up toqueries. To our knowledge, this is the first beyond-birthday security result forKAFwithout assuming completely independent round-keys.Our results hold in the multi-user setting as well, constituting the first non-trivial multi-user provable security results on Feistel ciphers. We finally demonstrate applications of our results on designing key-schedules and instantiating keyed sponge constructions.