- Conference Article
- 10.1145/3701100.3701263
Analysis of Security for a New Kind of an Extended Generalized Feistel Network
- Sep 27, 2024
- Xinfeng Dong + 4 more +4
Differential cryptanalysis and linear cryptanalysis are two classic analytical methods for block ciphers, and they are of great significance for evaluating the security of block ciphers. In practical security evaluations, a commonly used approach is to study lower bounds on the number of active F-functions in multi-round differential characteristics and linear approximations of the cipher structure, thereby establishing upper bounds on the maximum differential characteristic probability and the maximum linear approximation probability. If these upper bounds are sufficiently small, the cipher structure is considered to have resistance against differential and linear cryptanalysis. Based on this, this paper conducts a detailed study on the resistance of a class of four-branch extended generalized Feistel networks against differential and linear cryptanalysis. Under the condition that the F-function is bijective, it is proven that the lower bound on the number of active F-functions in \(k\)-round (\(k \ge 1\)) differential characteristics or linear approximations is \(k - 1\). Thus, if the maximum differential probability and the maximum linear approximation probability of the F-function are denoted as \(p\) and \(q\), respectively, the upper bounds on the \(k\)-round differential characteristic probability and linear approximation probability are \({p}^{k - 1}\) and \({q}^{k - 1}\), respectively.
Read more