Revisiting Key-alternating Feistel Ciphers for Shorter Keys and Multi-user Security
Revisiting Key-alternating Feistel Ciphers for Shorter Keys and Multi-user Security
复制标题
DOI:
10.1007/978-3-030-03326-2_8
复制
发表时间:
2018-12
期刊:
影响因子:
--
通讯作者:
Chun Guo;Lei Wang
中科院分区:
文献类型:
--
作者:
Chun Guo;Lei Wang
Key-Alternating Feistel (KAF) ciphers, a.k.a. Feistel-2 models, refer to Feistel networks with round functions of the form, whereis the (secret) round-key andis apublicrandom function. This model roughly captures the structures of many famous Feistel ciphers, and the most prominent instance is DES.Existing provable security results onKAFassumed independent round-keys and round functions (ASIACRYPT 2004 & FSE 2014). In this paper, we investigate how to achieve security under simpler and more realistic assumptions: with round-keys derived from a short main-key, and hopefully with identical round functions.For birthday-type security, we consider 4-roundKAF, investigate the minimal conditions on the way to derive the four round-keys, and prove that when such adequately derived keys and the same round function are used, the 4-roundKAFis secure up toqueries.For beyond-birthday security, we focus on 6-roundKAF. We prove that when the adjacent round-keys are independent, and independent round-functions are used, the 6 roundKAFis secure up toqueries. To our knowledge, this is the first beyond-birthday security result forKAFwithout assuming completely independent round-keys.Our results hold in the multi-user setting as well, constituting the first non-trivial multi-user provable security results on Feistel ciphers. We finally demonstrate applications of our results on designing key-schedules and instantiating keyed sponge constructions.