Paper 2010/426

Parallelizing the Camellia and SMS4 Block Ciphers - Extended version

Huihui Yap, Khoongming Khoo, and Axel Poschmann


The n-cell GF-NLFSR (Generalized Feistel-NonLinear Feedback Shift Register) structure [8] is a generalized unbalanced Feistel network that can be considered as a generalization of the outer function FO of the KASUMI block cipher. An advantage of this cipher over other n-cell generalized Feistel networks, e.g. SMS4 [11] and Camellia [5], is that it is parallelizable for up to n rounds. In hardware implementations, the benefits translate to speeding up encryption by up to n times while consuming similar area and significantly less power. At the same time n-cell GF-NLFSR structures offer similar proofs of security against differential cryptanalysis as conventional n-cell Feistel structures. We also ensure that parallelized versions of Camellia and SMS4 are resistant against other block cipher attacks such as linear, boomerang, integral, impossible differential, higher order differential,interpolation, slide, XSL and related-key differential attacks.

Note: 1. We added an explanation of the duality between differential and linear cryptanalysis for the p-Camellia and p-SMS4 structures. 2. We corrected a slight notational error in the proof of protection against linear cryptanalysis for p-Camellia in the conference paper. 3. We added a proof for protection against linear cryptanalysis for p-SMS4, which was not presented in the conference paper. 4. We did a hardware implementation of p-Camellia and p-SMS4 and presented the speed-up over Camellia, SMS4 in this extended paper. 5. We added test vectors for p-Camellia and p-SMS4.

Available format(s)
Secret-key cryptography
Publication info
Published elsewhere. Extended version of paper in Africacrypt 2010
Generalized Unbalanced Feistel NetworkGF-NLFSRCamelliaSMS4
Contact author(s)
yhuihui @ dso org sg
2010-08-03: last of 2 revisions
2010-08-01: received
See all versions
Short URL
Creative Commons Attribution


      author = {Huihui Yap and Khoongming Khoo and Axel Poschmann},
      title = {Parallelizing the Camellia and SMS4 Block Ciphers - Extended version},
      howpublished = {Cryptology ePrint Archive, Paper 2010/426},
      year = {2010},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.