10-Round Feistel is Indifferentiable from an Ideal Cipher.
Dana Dachman-Soled, Jonathan I. Katz, Aishwarya Thiruvengadam · 2015
We revisit the question of constructing an ideal cipher from a random oracle. Coron et al. (Journal of Cryptology, 2014) proved that a 14-round Feistel network using random, inde-pendent, keyed round functions is indifferentiable from an ideal cipher, thus demonstrating the feasibility of such a construction. Left unresolved is the best possible efficiency of the transfor-mation. We improve upon the result of Coron et al. and show that 10 rounds suffice. 1