Paper 2026/1040

Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type Designs

Tingting Guo, Ningbo University of Technology
Peng Wang, University of Chinese Academy of Sciences
Jiwu Jing, University of Chinese Academy of Sciences
Shuping Mao, Beijing Electronic Science and Technology Institute
Gang Liu, National Key Laboratory of Security Communication
Abstract

The Feistel (Luby-Rackoff) structure underlies numerous block-cipher and mode-of-operation designs, whose security is traditionally assessed via indistinguishability. For low-round Feistel constructions, a variety of classical and quantum distinguishing attacks are known. In this work, we show that such distinguishing attacks can be systematically upgraded to full plaintext recovery with essentially the same query complexity. We establish classical recovery attacks on the $2$-round Feistel under CPA and the $3$-round Feistel under CCA using only three queries, and introduce quantum-assisted forward/backward extension techniques based on Simon’s algorithm that yield recovery attacks on the $3$-round Feistel under qCPA and the $4$-round Feistel under qCCA. We further prove that the attacks extend to the Unified Feistel-Lai-Massey (UFLM) framework and therefore apply to a broad class of two-branch constructions. As a consequence, we obtain plaintext-recovery attacks on $4/5/6$-round Feistel-FK and on several practical enciphering schemes, including AEZ-core, FMix, OleF, double-decker, and docked-double-decker. Overall, our results reveal a fundamental connection between distinguishing and full plaintext recovery in low-round two-branch Feistel-type designs, in both classical and quantum settings.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in CRYPTO 2026
Keywords
FeistelLuby-RackoffLai-MasseyUFLMFull plaintext recovery attackTruncated boomerang differential
Contact author(s)
guotingting @ nbut edu cn
p-wang @ ucas ac cn
jwjing @ ucas ac cn
maoshuping19 @ mails ucas ac cn
liugang @ hnu edu cn
History
2026-06-08: last of 3 revisions
2026-05-23: received
See all versions
Short URL
https://ia.cr/2026/1040
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2026/1040,
      author = {Tingting Guo and Peng Wang and Jiwu Jing and Shuping Mao and Gang Liu},
      title = {Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type Designs},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1040},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1040}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.