UFLM: A Unified Framework for Feistel Structure and Lai-Massey Structure
摘要
Feistel structure and Lai-Massey structure are 2-branch structures with the property that encryption is similar to decryption. Many cryptographers study these two structures individually regarding design, provable security, and cryptanalysis. This paper adopts a unified perspective to research these two structures. We propose a framework called UFLM. Feistel structure and Lai-Massey structure are instances of UFLM. The differences between these two structures stem from the varying orders of branch permutation and orthomorphic permutation as viewed from the perspective of UFLM. Specifically, the order of the branch permutation is 2, while the order of an orthomorphic permutation is at least 3. We further investigate the number of rounds of impossible differentials, zero correlation linear hulls, and integral distinguishers of UFLM instances with bijective f-functions based on different orders of the linear transformation adopted. Finally, we prove the CCA security of 4-round UFLM construction using secret random f-functions in two cases. Interestingly, the CCA security of 4-round Lai-Massey construction is superior to that of 4-round Feistel construction when utilizing the same f-function in each round. The results can be easily transferred to random permutation-based UFLM constructions. With these, the Lai-Massey structure does benefit from orthomorphic permutation in both cryptanalysis and provable security settings. We further provide a UFLM instance that is better than Feistel structure regarding several distinguishers, which may be beneficial for future block cipher designs.