Paper 2026/1040
Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type Designs
Abstract
The Feistel (Luby-Rackoff) structure underlies numerous block-cipher and mode-of-operation designs, whose security is traditionally assessed via indistinguishability. For low-round Feistel constructions, a variety of classical and quantum distinguishing attacks are known. In this work, we show that such distinguishing attacks can be systematically upgraded to full plaintext recovery with essentially the same query complexity. We establish classical recovery attacks on the $2$-round Feistel under CPA and the $3$-round Feistel under CCA using only three queries, and introduce quantum-assisted forward/backward extension techniques based on Simon’s algorithm that yield recovery attacks on the $3$-round Feistel under qCPA and the $4$-round Feistel under qCCA. We further prove that the attacks extend to the Unified Feistel-Lai-Massey (UFLM) framework and therefore apply to a broad class of two-branch constructions. As a consequence, we obtain plaintext-recovery attacks on $4/5/6$-round Feistel-FK and on several practical enciphering schemes, including AEZ-core, FMix, OleF, double-decker, and docked-double-decker. Overall, our results reveal a fundamental connection between distinguishing and full plaintext recovery in low-round two-branch Feistel-type designs, in both classical and quantum settings.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- A minor revision of an IACR publication in CRYPTO 2026
- Keywords
- FeistelLuby-RackoffLai-MasseyUFLMFull plaintext recovery attackTruncated boomerang differential
- Contact author(s)
-
guotingting @ nbut edu cn
p-wang @ ucas ac cn
jwjing @ ucas ac cn
maoshuping19 @ mails ucas ac cn
liugang @ hnu edu cn - History
- 2026-06-08: last of 3 revisions
- 2026-05-23: received
- See all versions
- Short URL
- https://ia.cr/2026/1040
- License
-
CC BY-NC-ND
BibTeX
@misc{cryptoeprint:2026/1040,
author = {Tingting Guo and Peng Wang and Jiwu Jing and Shuping Mao and Gang Liu},
title = {Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type Designs},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1040},
year = {2026},
url = {https://eprint.iacr.org/2026/1040}
}