New results on pseudorandom permutation generators based on the des scheme

47Citations
Citations of this article
40Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

We denote by Ψk the permutation generator based on the DES Scheme with k rounds where the S boxes are replaced by random independant functions. We denote by |P1 - P1*|, (respectively |P1 - P1**|), the probability of distinguishing such a permutation from a random function (respectively from a random permutation) by means of a distinguishing circuit that has m oracle gates. In 1988, M. Luby and C. Rackoff [1] proved that ∀k≥3, |P1-P1*|≤m(m-1)/2n. At Eurocrypt 90, J. Pieprzyk wondered at the end of his paper [4] if that inequality could be improved. This is the problem we consider here. In particular, such an improvement could greatly reduce the length of the keys used in a “direct” application of these theorems to a cryptosystem. Our main results will be: 1. For Ψ3 and Ψ4 there is no really tighter inequality than |P1-P1*| ≤m(m-1)/2n. 2. However for Ψ5 (and then for Ψk, k ≥ 5), there is a much tighter inequality than Luby - Rackoff’s one. For example for Ψ6, |P1-P1*| and |P1-P1**| are ≤12m/2n+18m3/22n. 3. When m is very small (m = 2 or 3 for example) it is possible to have an explicit evaluation of the effects of the number of rounds k on the “better and better pseudorandomness” of Ψk.

Cite

CITATION STYLE

APA

Patarin, J. (1992). New results on pseudorandom permutation generators based on the des scheme. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 576 LNCS, pp. 301–312). Springer Verlag. https://doi.org/10.1007/3-540-46766-1_25

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free