Paper 2025/914

Tweakable Permutation-based Luby-Rackoff Constructions

Bishwajit Chakraborty, Nanyang Technological University, Singapore
Abishanka Saha, Eindhoven University of Technology, The Netherlands
Abstract

Liskov, Rivest, and Wagner, in their seminal work, formulated tweakable blockciphers and proposed two blockcipher-based design paradigms, LRW1 and LRW2, where the basic design strategy is to xor the masked tweak to the input and output of a blockcipher. The 2-round cascaded LRW2 and 4-round cascaded LRW1 have been proven to be secure up to $\mathcal{O}(2^{3n/4})$ queries, but $n$-bit optimal security still remains elusive for these designs. In their paper, Liskov also posed an open challenge of embedding the tweak directly in the blockcipher, and to address this, Goldenberg et al. introduced the tweakable Luby-Rackoff (LR) constructions. They showed that if the internal primitives are random functions, then for tweaks with $t$ blocks, the construction needs $t + 6$ rounds to be optimally $n$-bit CPA secure and $2t + 8$ rounds to be optimally $n$-bit CCA secure, where respectively $t$ and $2t$ rounds were required to process the tweaks. Since blockciphers can be designed much more efficiently than pseudorandom functions, in many practical applications the internal primitives of LR ciphers are instantiated as blockciphers, which however would lead to a birthday-bound factor, which is not ideal for say lightweight cryptography. This paper addresses the following two key questions affirmatively: (1) Can Goldenberg et al.'s results be extended to LR constructions with random permutations as internal primitives without compromising the optimal $n$-bit security? (2) Can the number of rounds required for handling long tweaks be reduced? We formally define TLR-compatible functions, for processing the tweak, which when composed with 4-rounds and 5-rounds of LR construction with random permutations as internal primitives gives us respectively $n$-bit CPA and CCA secure tweakable permutations. For the security analysis, we proved general Mirror Theory result for three permutations. We also propose instantiating TLR-compatible functions with one round LR where a permutation (resp, two AXU hash functions) is used to mask single-block tweaks (resp., variable-length tweaks), thus proposing the $n$-bit CPA (resp., CCA) secure tweakable permutation candidates, $\mathsf{TLRP5}$ and $\mathsf{TLRP5+}$ (resp., $\mathsf{TLRP7}$ and $\mathsf{TLRP7+}$), using $5$ (resp., $7$) LR rounds, which is a significant reduction from the tweak-length-dependent results of Goldenberg et al. We further extend the implications of our analysis of permutation-based LR as follows: (1) We show $n$-bit CPA (resp., CCA) security of $5$-rounds (resp. $7$-rounds) permutation-based LR construction, which is quite an improvement over the existing $2n/3$-bit security proved by Guo et al. (2) We propose a new design paradigm, $\mathsf{DbHtF}$, for $n$-bit secure MACs, that involves hashing the message, then passing the diblock tag through four rounds of permutation-based LR and then truncating the left block.

Note: Addendum: We have noticed another implication of our analysis, which is that we get optimally secure MAC constructions from permutation-based LR, and these results are presented in the newly added Section 8 : The $\mathsf{DbHtF}$ MAC Family. This will not appear in the CRYPTO 2025 version either.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Variable-length TweakTweakable block cipherPermutation-based Feistel ConstructionOptimal security.
Contact author(s)
bishu math ynwa @ gmail com
sahaa 1993 @ gmail com
History
2025-06-11: last of 4 revisions
2025-05-21: received
See all versions
Short URL
https://ia.cr/2025/914
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/914,
      author = {Bishwajit Chakraborty and Abishanka Saha},
      title = {Tweakable Permutation-based Luby-Rackoff Constructions},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/914},
      year = {2025},
      url = {https://eprint.iacr.org/2025/914}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.