{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:18:29Z","timestamp":1760242709983,"version":"build-2065373602"},"reference-count":23,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2016,4,1]],"date-time":"2016-04-01T00:00:00Z","timestamp":1459468800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Cryptography"],"abstract":"<jats:p>The r-rounds Even\u2013Mansour block cipher is a generalization of the well known Even\u2013Mansour block cipher to r iterations. Attacks on this construction were described by Nikoli\u0107 et al. and Dinur et al. for     r = 2 , 3    . These attacks are only marginally better than brute force but are based on an interesting observation (due to Nikoli\u0107 et al.): for a \u201ctypical\u201d permutation P, the distribution of     P ( x ) \u2295 x     is not uniform. This naturally raises the following question. Let us call permutations for which the distribution of     P ( x ) \u2295 x     is uniformly \u201cbalanced\u201d \u2014 is there a sufficiently large family of balanced permutations, and what is the security of the resulting Even\u2013Mansour block cipher? We show how to generate families of balanced permutations from the Luby\u2013Rackoff construction and use them to define a     2 n    -bit block cipher from the 2-round Even\u2013Mansour scheme. We prove that this cipher is indistinguishable from a random permutation of      { 0 , 1 }   2 n     , for any adversary who has oracle access to the public permutations and to an encryption\/decryption oracle, as long as the number of queries is     o (  2  n \/ 2   )    . As a practical example, we discuss the properties and the performance of a 256-bit block cipher that is based on our construction, and uses the Advanced Encryption Standard (AES), with a fixed key, as the public permutation.<\/jats:p>","DOI":"10.3390\/cryptography1010002","type":"journal-article","created":{"date-parts":[[2016,4,1]],"date-time":"2016-04-01T10:31:20Z","timestamp":1459506680000},"page":"2","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Balanced Permutations Even\u2013Mansour Ciphers"],"prefix":"10.3390","volume":"1","author":[{"given":"Shoni","family":"Gilboa","sequence":"first","affiliation":[{"name":"Department of Mathematics and Computer Science, The Open University of Israel, Raanana 4353701, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shay","family":"Gueron","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Haifa, Haifa 3498838, Israel"},{"name":"Intel Corporation, Israel Development Center, Haifa 31015, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1029-6576","authenticated-orcid":false,"given":"Mridul","family":"Nandi","sequence":"additional","affiliation":[{"name":"Indian Statistical Institute, Kolkata 700108, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2016,4,1]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1007\/978-3-642-29011-4_5","article-title":"Key-alternating ciphers in a provable setting: Encryption using a small number of public permutations (extended abstract)","volume":"Volume 7237","author":"Bogdanov","year":"2012","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2012"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/s001459900025","article-title":"A construction of a cipher from a single pseudorandom permutation","volume":"10","author":"Even","year":"1997","journal-title":"J. Cryptol."},{"key":"ref_3","first-page":"495","article-title":"Limitations of the Even\u2013Mansour construction","volume":"Volume 739","author":"Daemen","year":"1991","journal-title":"Advances in Cryptology\u2014ASIACRYPT 1991"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1007\/978-3-642-55220-5_19","article-title":"Tight security bounds for key-alternating ciphers","volume":"Volume 8441","author":"Chen","year":"2014","journal-title":"Advances in Cryptology\u2014EUROCRYPT 2014"},{"key":"ref_5","unstructured":"Steinberger, J.P. Improved Security Bounds for Key-Alternating Ciphers via Hellinger Distance. Available online: http:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.348.6401&rep=rep1&type=pdf."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"278","DOI":"10.1007\/978-3-642-34961-4_18","article-title":"An Asymptotically Tight Security Analysis of the Iterated Even\u2013Mansour Cipher","volume":"Volume 7658","author":"Lampe","year":"2012","journal-title":"Advances in Cryptology\u2014ASIACRYPT 2012"},{"key":"ref_7","first-page":"112","article-title":"Cryptanalysis of Round-Reduced LED","volume":"Volume 8424","author":"Wang","year":"2013","journal-title":"Fast Software Encryption\u2014FSE 2013"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"337","DOI":"10.1007\/978-3-642-42033-7_18","article-title":"Key Recovery Attacks on 3-round Even\u2013Mansour, 8-step LED-128, and full AES2","volume":"Volume 8269","author":"Dinur","year":"2013","journal-title":"Advances in Cryptology\u2014ASIACRYPT 2013"},{"key":"ref_9","first-page":"21","article-title":"Indifferentiability, impossibility results on reductions, and applications to the random oracle methodology","volume":"Volume 2951","author":"Maurer","year":"2004","journal-title":"Theory of Cryptography"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/978-3-540-85174-5_1","article-title":"The random oracle model and the ideal cipher model are equivalent","volume":"Volume 5157","author":"Coron","year":"2008","journal-title":"Advances in Cryptology\u2014CRYPTO 2008"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1007\/978-3-540-30539-2_3","article-title":"Eliminating random permutation oracles in the Even\u2013Mansour ciphe","volume":"Volume 3329","author":"Gentry","year":"2004","journal-title":"Advances in Cryptology\u2014ASIACRYPT 2004"},{"key":"ref_12","first-page":"243","article-title":"Security Analysis of Key-Alternating Feistel Ciphers","volume":"Volume 8540","author":"Lampe","year":"2014","journal-title":"Fast Software Encryption\u2014FSE 2014"},{"key":"ref_13","unstructured":"Patarin, J. (1991). \u00c9tude Des g\u00e9n\u00e9rateurs de Permutations Pseudo-al\u00e9atoires bas\u00e9s Sur le Sch\u00e9ma du D.E.S. [Ph.D. Thesis, National Institute for Research in Computer Science and Control (INRIA)]."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"513","DOI":"10.1007\/978-3-540-45146-4_30","article-title":"Luby\u2013Rackoff: 7 rounds are enough for 2n(1 \u2212 \u03b5) security","volume":"Volume 2729","author":"Patarin","year":"2003","journal-title":"Advances in Cryptology\u2014CRYPTO 2003"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"233","DOI":"10.1007\/s10623-005-3562-2","article-title":"Luby\u2013Rackoff revisited: On the use of permutations as inner functions of a Feistel scheme","volume":"39","author":"Piret","year":"2006","journal-title":"Des. Codes Cryptogr."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1007\/978-3-642-02384-2_4","article-title":"Generic attacks on Feistel networks with internal permutations","volume":"Volume 5580","author":"Treger","year":"2009","journal-title":"Progress in Cryptology\u2014AFRICACRYPT 2009"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1007\/978-3-642-17401-8_7","article-title":"The characterization of Luby\u2013Rackoff and its optimum single-key variants","volume":"Volume 6498","author":"Nandi","year":"2010","journal-title":"Progress in Cryptology\u2014INDOCRYPT 2010"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Mouha, N., and Luykx, A. (2015). Multi-Key Security: The Even\u2013Mansour Construction Revisited, In Advances in Cryptology\u2014CRYPTO 2015, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-662-47989-6_10"},{"key":"ref_19","unstructured":"Announcing Request for Candidate Algorithm Nominations for the Advanced Encryption Standard (AES), Available online: http:\/\/csrc.nist.gov\/CryptoToolkit\/aes\/pre-round1\/aes_9709.htm."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"315","DOI":"10.1007\/978-3-540-76900-2_19","article-title":"Known-Key Distinguishers for Some Block Ciphers","volume":"Volume 4833","author":"Knudsen","year":"2007","journal-title":"Advances in Cryptology\u2014ASIACRYPT 2007"},{"key":"ref_21","first-page":"365","article-title":"Super-Sbox Cryptanalysis: Improved Attacks for AES-Like Permutations","volume":"Volume 6147","author":"Gilbert","year":"2010","journal-title":"Fast Software Encryption\u2014FSE 2010"},{"key":"ref_22","unstructured":"Daemen, J., and Rijmen, V. AES Proposal: Rijndael (National Institute of Standards and Technology), Available online: http:\/\/csrc.nist.gov\/archive\/aes\/rijndael\/Rijndael-ammended.pdf."},{"key":"ref_23","unstructured":"Gueron, S. Intel Advanced Encryption Standard (AES) Instructions Set (Rev 3.01). Available online: http:\/\/software.intel.com\/sites\/default\/files\/article\/165683\/aes-wp-2012-09-22-v01.pdf."}],"container-title":["Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2410-387X\/1\/1\/2\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:21:40Z","timestamp":1760210500000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2410-387X\/1\/1\/2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,4,1]]},"references-count":23,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2017,6]]}},"alternative-id":["cryptography1010002"],"URL":"https:\/\/doi.org\/10.3390\/cryptography1010002","relation":{},"ISSN":["2410-387X"],"issn-type":[{"type":"electronic","value":"2410-387X"}],"subject":[],"published":{"date-parts":[[2016,4,1]]}}}