Using MILP in Analysis of Feistel Structures and Improving Type II GFS by Switching Mechanism

  • Mahdi Sajadieh
  • Mohammad Vaziri
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 11356)


Some features of Feistel structures have caused them to be considered as an efficient structure for design of block ciphers. Although several structures are proposed relied on Feistel structure, the type-II generalized Feistel structures (GFS) based on SP-functions are more prominent. Because of difference cancellation, which occurs in Feistel structures, their resistance against differential and linear attack is not as expected. In order to improve the immunity of Feistel structures against differential and linear attack, two methods are proposed. One of them is using multiple MDS matrices, and the other is using changing permutations of sub-blocks.

In this paper by using mixed-integer linear programming (MILP) and summation representation method, a technique to count the active S-boxes is proposed. Moreover in some cases, the results proposed by Shibutani at SAC 2010 are improved. Also multiple MDS matrices are applied to GFS, and by relying on a proposed approach, the new inequalities related to using multiple MDS matrices are extracted, and results of using the multiple MDS matrices in type II GFS are evaluated. Finally results related to linear cryptanalysis are presented. Our results show that using multiple MDS matrices leads to \(22\%\) and \(19\%\) improvement in differential cryptanalysis of standard and improved 8 sub-blocks structures, respectively, after 18 rounds.


MILP Generalized Feistel structure Switching mechanism Differential cryptanalysis Linear cryptanalysis 


  1. 1.
    Aoki, K., et al.: Camellia: a 128-bit block cipher suitable for multiple platforms — design and analysis. In: Stinson, D.R., Tavares, S. (eds.) SAC 2000. LNCS, vol. 2012, pp. 39–56. Springer, Heidelberg (2001). Scholar
  2. 2.
    Beierle, C., et al.: The SKINNY family of block ciphers and its low-latency variant MANTIS. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016, Part II. LNCS, vol. 9815, pp. 123–153. Springer, Heidelberg (2016). Scholar
  3. 3.
    Bogdanov, A.: On unbalanced feistel networks with contracting MDS diffusion. Des. Codes Crypt. 59(1), 3558 (2011)MathSciNetzbMATHGoogle Scholar
  4. 4.
  5. 5.
    Kanda, M.: Practical security evaluation against differential and linear cryptanalyses for feistel ciphers with SPN round function. In: Stinson, D.R., Tavares, S. (eds.) SAC 2000. LNCS, vol. 2012, pp. 324–338. Springer, Heidelberg (2001). Scholar
  6. 6.
    Mouha, N., Wang, Q., Gu, D., Preneel, B.: Differential and linear cryptanalysis using mixed-integer linear programming. In: Wu, C.-K., Yung, M., Lin, D. (eds.) Inscrypt 2011. LNCS, vol. 7537, pp. 57–76. Springer, Heidelberg (2012). Scholar
  7. 7.
    Sajadieh, M., Mirzaei, A., Mala, H., Rijmen, V.: A new counting method to bound the number of active s-boxes in Rijndael and 3D. Des. Codes Crypt. 83(2), 327–343 (2017)MathSciNetCrossRefGoogle Scholar
  8. 8.
    Shibutani, K.: On the diffusion of generalized feistel structures regarding differential and linear cryptanalysis. In: Biryukov, A., Gong, G., Stinson, D.R. (eds.) SAC 2010. LNCS, vol. 6544, pp. 211–228. Springer, Heidelberg (2011). Scholar
  9. 9.
    Shirai, T., Araki, K.: On generalized feistel structures using the diffusion switching mechanism. IEICE Trans. Fundam. Electron. Commun. Comput. Sci. E91-A(8), 2120–2129 (2008)CrossRefGoogle Scholar
  10. 10.
    Shirai, T., Kanamaru, S., Abe, G.: Improved upper bounds of differential and linear characteristic probability for camellia. In: Daemen, J., Rijmen, V. (eds.) FSE 2002. LNCS, vol. 2365, pp. 128–142. Springer, Heidelberg (2002). Scholar
  11. 11.
    Shirai, T., Shibutani, K.: Improving immunity of feistel ciphers against differential cryptanalysis by using multiple MDS matrices. In: Roy, B., Meier, W. (eds.) FSE 2004. LNCS, vol. 3017, pp. 260–278. Springer, Heidelberg (2004). Scholar
  12. 12.
    Shirai, T., Shibutani, K.: On feistel structures using a diffusion switching mechanism. In: Robshaw, M. (ed.) FSE 2006. LNCS, vol. 4047, pp. 41–56. Springer, Heidelberg (2006). Scholar
  13. 13.
    Shirai, T., Shibutani, K., Akishita, T., Moriai, S., Iwata, T.: The 128-Bit blockcipher CLEFIA (Extended Abstract). In: Biryukov, A. (ed.) FSE 2007. LNCS, vol. 4593, pp. 181–195. Springer, Heidelberg (2007). Scholar
  14. 14.
    Suzaki, T., Minematsu, K.: Improving the generalized feistel. In: Hong, S., Iwata, T. (eds.) FSE 2010. LNCS, vol. 6147, pp. 19–39. Springer, Heidelberg (2010). Scholar

Copyright information

© Springer Nature Switzerland AG 2018

Authors and Affiliations

  1. 1.Department of Electrical Engineering, Khorasgan BranchIslamic Azad UniversityIsfahanIran
  2. 2.Department of MathematicsIran University of Science and Technology (IUST)TehranIran

Personalised recommendations