Distinguishing Attacks on a Kind of Generalized Unbalanced Feistel Network.

Ruilin Li, Bing Sun, Chao Li · 2009

Abstract. Recently, a new kind of Generalized Unbalanced Feistel Network, denoted as GUFN-n, is proposed by Choy et al. at ACISP 2009. The advantages of this structure are that it allows parallel computations for encryption and it can provide provable security against traditional differential and linear cryptanalysis given that the round function is bijective. For this new structure, the designers also found a (2n − 1)-round impossible differential and a (3n − 1)-round integral distinguisher. In this paper, we study distinguishing attacks on GUFN-n. We find an n 2-round integral distinguisher and show that it can be simply extended to an (n 2 + n − 2)-round higher-order integral distinguisher. Moreover, we point out that the n 2-round integral distinguisher corresponds to an n 2-round truncated differential with probability 1, based on which an impossible differential with up to (n 2 + n − 2)-round can be constructed. At last, we describe a variant structure of GUFN-n, denoted as GUFN ∗-n, where the round function is F (x ⊕ K). For this variant structure, we present a new kind of n 2-round non-surjective distinguisher and use it to attack GUFN ∗-n with very low data complexity.

Read the paper · More papers on PaperTik