Paper 2025/1678
Two-Key Variant of the Four-Round Cascading LRW1
Abstract
In EUROCRYPT'20, Bao et al. have proved that three rounds of cascaded LRW1 construction provide security up to $2^{2n/3}$ queries. However, in a recent work by Khairallah et al., it has been shown that the construction provides only birthday bound security via exhibiting a distinguishing attack on the construction, and thereby invalidating the claim of Bao et al. In an independent and contemporaneous work, Datta et al. have shown that four rounds of cascading of the $\textsf{LRW1}$ construction, dubbed as $\textsf{CLRW1}^4$—based on four independent keyed block ciphers—achieves $3n/4$-bit CCA security. In this paper, we have shown that a key reduced variant of the $\textsf{CLRW1}^4$ construction, dubbed as $\textsf{R}\mbox{-}\textsf{CLRW1}^4$ based on two independent keyed block ciphers, achieves $2n/3$-bit CCA security. The security proof of our construction relies on a heavy use of the H-Coefficient technique and non-trivial analysis in lower-bounding the real interpolation probability for good transcripts.
Note: This paper has been accepted in Designs, Codes and Cryptography (DCC), 2025, under the title “Two-Key Variant of the Four-Round Cascading LRW1”.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published elsewhere. Designs, Codes and Cryptography (DCC), 2025
- Keywords
- Tweakable Block CipherCascaded LRWBeyond Birthday BoundMirror TheoryH-Coefficients Technique
- Contact author(s)
-
shreya dey @ tcgcrest org
avijit dutta @ tcgcrest org
k-minematsu @ nec com - History
- 2025-09-18: approved
- 2025-09-16: received
- See all versions
- Short URL
- https://ia.cr/2025/1678
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1678,
author = {Shreya Dey and Avijit Dutta and Kazuhiko Minematsu},
title = {Two-Key Variant of the Four-Round Cascading {LRW1}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1678},
year = {2025},
url = {https://eprint.iacr.org/2025/1678}
}