Paper 2011/705

Differential Attacks on Generalized Feistel Schemes

Valerie Nachef, Emmanuel Volte, and Jacques Patarin


While generic attacks on classical Feistel schemes and unbalanced Feistel schemes have been studied a lot, generic attacks on several generalized Feistel schemes like type-1, type-2 and type-3 and Alternating Feistel schemes, as defined in~\cite{HR}, have not been systematically investigated. This is the aim of this paper. We give our best Known Plaintext Attacks and non-adaptive Chosen Plaintext Attacks on these schemes and we determine the maximum number of rounds that we can attack. It is interesting to have generic attacks since there are well known block cipher networks that use generalized Feistel schemes: CAST-256 (type-1), RC-6 (type-2), MARS (type-3) and BEAR/LION (alternating). Also, Type-1 and Type-2 Feistel schemes are respectively used in the construction of the hash functions $Lesamnta$ and $SHAvite-3_{512}$.

Available format(s)
Secret-key cryptography
Publication info
Published elsewhere. Unknown where it was published
generalized Feistel schemesgeneric attacks on encryption schemesblock ciphers
Contact author(s)
valerie nachef @ u-cergy fr
2011-12-27: revised
2011-12-27: received
See all versions
Short URL
Creative Commons Attribution


      author = {Valerie Nachef and Emmanuel Volte and Jacques Patarin},
      title = {Differential Attacks on Generalized Feistel Schemes},
      howpublished = {Cryptology ePrint Archive, Paper 2011/705},
      year = {2011},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.