<p>In this paper, we re-investigate the Lai–Massey scheme, originally proposed in the cipher IDEA. Due to the similarity with the Feistel networks, and due to the existence of invariant subspace attacks as originally pointed out by Vaudenay at FSE 1999, the Lai–Massey scheme has received only little attention by the community. As first contribution, we propose two new generalizations of such scheme that are not (extended) affine equivalent to any generalized Feistel network proposed in the literature so far. Then, inspired by the recent <Emphasis FontCategory="NonProportional">Horst</Emphasis> construction, we propose the <Emphasis FontCategory="NonProportional">Amaryllises</Emphasis> structure as a generalization of the Lai–Massey scheme, in which the linear combination in the Lai–Massey scheme can be replaced by a non-linear one. Besides proposing concrete examples of the <Emphasis FontCategory="NonProportional">Amaryllises</Emphasis> construction, we analyze its cryptographic properties in the context of MPC-/HE-/ZK-friendly symmetric primitives.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On generalizations of the Lai–Massey scheme

  • Lorenzo Grassi

摘要

In this paper, we re-investigate the Lai–Massey scheme, originally proposed in the cipher IDEA. Due to the similarity with the Feistel networks, and due to the existence of invariant subspace attacks as originally pointed out by Vaudenay at FSE 1999, the Lai–Massey scheme has received only little attention by the community. As first contribution, we propose two new generalizations of such scheme that are not (extended) affine equivalent to any generalized Feistel network proposed in the literature so far. Then, inspired by the recent Horst construction, we propose the Amaryllises structure as a generalization of the Lai–Massey scheme, in which the linear combination in the Lai–Massey scheme can be replaced by a non-linear one. Besides proposing concrete examples of the Amaryllises construction, we analyze its cryptographic properties in the context of MPC-/HE-/ZK-friendly symmetric primitives.