Paper 2015/711

Construction of Lightweight S-Boxes using Feistel and MISTY structures (Full Version)

Anne Canteaut, Sébastien Duval, and Gaëtan Leurent


The aim of this work is to find large S-Boxes, typically operating on 8 bits, having both good cryptographic properties and a low implementation cost. Such S-Boxes are suitable building-blocks in many lightweight block ciphers since they may achieve a better security level than designs based directly on smaller S-Boxes. We focus on S-Boxes corresponding to three rounds of a balanced Feistel and of a balanced MISTY structure, and generalize the recent results by Li and Wang on the best differential uniformity and linearity offered by such a construction. Most notably, we prove that Feistel networks supersede MISTY networks for the construction of 8-bit permutations. Based on these results, we also provide a particular instantiation of an 8-bit permutation with better properties than the S-Boxes used in several ciphers, including Robin, Fantomas or CRYPTON.

Available format(s)
Secret-key cryptography
Publication info
Published elsewhere. MAJOR revision.SAC 2015
S-BoxFeistel networkMISTY networkLightweight block-cipher
Contact author(s)
gaetan leurent @ inria fr
2015-07-18: received
Short URL
Creative Commons Attribution


      author = {Anne Canteaut and Sébastien Duval and Gaëtan Leurent},
      title = {Construction of Lightweight S-Boxes using Feistel and MISTY structures (Full Version)},
      howpublished = {Cryptology ePrint Archive, Paper 2015/711},
      year = {2015},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.