{"entities":{"Q1369725":{"pageid":1380465,"ns":120,"title":"Item:Q1369725","lastrevid":68564961,"modified":"2026-04-13T00:35:37Z","type":"item","id":"Q1369725","labels":{"en":{"language":"en","value":"On weaknesses of non-surjective round functions"}},"descriptions":{"en":{"language":"en","value":"scientific article; zbMATH DE number 1076981"}},"aliases":{},"claims":{"P31":[{"mainsnak":{"snaktype":"value","property":"P31","hash":"fd5912e4dab4b881a8eb0eb27e7893fef55176ad","datavalue":{"value":{"entity-type":"item","numeric-id":56887,"id":"Q56887"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$D903F8ED-2199-4258-B397-5D1DD57A7DEA","rank":"normal"}],"P159":[{"mainsnak":{"snaktype":"value","property":"P159","hash":"31553b98db5227e9186fb27d002c00c5887677a9","datavalue":{"value":{"text":"On weaknesses of non-surjective round functions","language":"en"},"type":"monolingualtext"},"datatype":"monolingualtext"},"type":"statement","id":"Q1369725$2D19C75C-43E5-42CD-9E4F-64DC3D36202A","rank":"normal"}],"P225":[{"mainsnak":{"snaktype":"value","property":"P225","hash":"74756f244f311d5b5410224a7ad748dfe33c9722","datavalue":{"value":"0890.94028","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q1369725$40C1F6EB-D016-40FC-A09F-00C4E04A20A1","rank":"normal"}],"P27":[{"mainsnak":{"snaktype":"value","property":"P27","hash":"0e6019199415b01ec433b84acd487987662887db","datavalue":{"value":"10.1023/A:1008224928678","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q1369725$FFC5A147-94DA-48C5-840E-0334F2DFE36E","rank":"normal"}],"P16":[{"mainsnak":{"snaktype":"value","property":"P16","hash":"86215e4e34be2f0059dfcc930becf72d8ed674a4","datavalue":{"value":{"entity-type":"item","numeric-id":522207,"id":"Q522207"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$1A129CB9-B0D2-454D-8A9D-3D26F147A2C6","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P16","hash":"698c1f29fc9b0201627d45fb7dc66da28f6d1144","datavalue":{"value":{"entity-type":"item","numeric-id":421041,"id":"Q421041"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$BD303766-0C4D-4E46-9E1F-BD6F5CE72DFD","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P16","hash":"96a5e8e736b5ac68bc81fac04ef9948946997c13","datavalue":{"value":{"entity-type":"item","numeric-id":1369724,"id":"Q1369724"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$DF149425-9069-4473-B49E-5A944E136598","rank":"normal"}],"P200":[{"mainsnak":{"snaktype":"value","property":"P200","hash":"fb34abbf39f11094509111953e4c62a22b1e3897","datavalue":{"value":{"entity-type":"item","numeric-id":115940,"id":"Q115940"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$0B333770-0BB4-4639-BEA1-B3E11B2B571B","rank":"normal"}],"P28":[{"mainsnak":{"snaktype":"value","property":"P28","hash":"b0eaf19f8434564cff6a93a80be5427b161bea94","datavalue":{"value":{"time":"+1998-01-07T00:00:00Z","timezone":0,"before":0,"after":0,"precision":11,"calendarmodel":"http://www.wikidata.org/entity/Q1985727"},"type":"time"},"datatype":"time"},"type":"statement","id":"Q1369725$8883A500-D44F-41D4-B78D-6D4DD99A0E48","rank":"normal"}],"P1448":[{"mainsnak":{"snaktype":"value","property":"P1448","hash":"dd99a4137c695e2eed16b2b9eef303ff21d54683","datavalue":{"value":"Generally, there are no doubts that the well-known DES is reaching the end of its lifetime. However, quite a lot of new ciphers aspiring to become its replacement keep the original Feistel structure of DES. Their novelty is usually based on suggesting new structures for the \\textit{round function}.    In the article weaknesses introduced by the use of non-surjective, or, more generally, non-uniform round functions in Feistel-type ciphers are studied. Assuming round keys are independent and uniformly distributed, it is shown how non-surjectivity of round function makes attack in a known-plaintext setting possible. The idea of the basic attack is then extended and an estimate for the number of known plaintexts that are needed for the attack is derived. In the rest of the paper the attack is applied to some members of CAST ciphers family as well as to LOKI91. It is shown that reducing the number of rounds to 6 or less makes the ciphers vulnerable to the statistical attack presented. In the last section some design principles for Feistel ciphers are discussed.","type":"string"},"datatype":"string"},"type":"statement","id":"Q1369725$D13D8BF0-8DB4-4B90-B33D-05EF181A8471","rank":"normal"}],"P226":[{"mainsnak":{"snaktype":"value","property":"P226","hash":"b3f5570531d36cdad95fcc8cba24a2dabc5fbbbf","datavalue":{"value":"94A60","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q1369725$2D795B40-491D-405E-BD93-594E675F76F4","rank":"normal"}],"P1451":[{"mainsnak":{"snaktype":"value","property":"P1451","hash":"34fa931abcebe117edb69f19528d17b52ab8219c","datavalue":{"value":"1076981","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q1369725$5B127405-5299-4896-9D77-0C90724DA4B4","rank":"normal"}],"P1450":[{"mainsnak":{"snaktype":"value","property":"P1450","hash":"0299de9541f93d5a0481756e73ae84803144af17","datavalue":{"value":"block cipher","type":"string"},"datatype":"string"},"type":"statement","id":"Q1369725$D1F82776-D71A-4C06-821E-7F7380DADEA0","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"0ca18a341e8b649b565a1d8f1ff707d449835862","datavalue":{"value":"cryptanalysis","type":"string"},"datatype":"string"},"type":"statement","id":"Q1369725$FAD7E979-5DDF-4F4D-A8EF-DD04C5DDA01C","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"3a9e36a926a1c24607ee8e7e505b66602a4882c8","datavalue":{"value":"attack on Feistel ciphers","type":"string"},"datatype":"string"},"type":"statement","id":"Q1369725$FE2A607D-85EB-4E5F-867A-575712893743","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"cb342663f7eaf410beba47eaa704252550fa337a","datavalue":{"value":"CAST algorithms","type":"string"},"datatype":"string"},"type":"statement","id":"Q1369725$393C3313-E759-492F-9C71-26A94F36784E","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1450","hash":"dad4966e393130db26cc169d292834a817e4f430","datavalue":{"value":"LOKI91","type":"string"},"datatype":"string"},"type":"statement","id":"Q1369725$3EC42BE6-D657-4C12-9508-2DC5263261A2","rank":"normal"}],"P1447":[{"mainsnak":{"snaktype":"value","property":"P1447","hash":"4418b7d4f2a0250db5c25bb23e561efd56a43eb7","datavalue":{"value":{"entity-type":"item","numeric-id":587571,"id":"Q587571"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$995F9CB1-E619-4BF6-B949-94B4DB188CB2","rank":"normal"}],"P1460":[{"mainsnak":{"snaktype":"value","property":"P1460","hash":"57f7fea50d2ce1b39b695c4a1313582eed405e38","datavalue":{"value":{"entity-type":"item","numeric-id":5976449,"id":"Q5976449"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","id":"Q1369725$82640E0F-E837-492F-A0CB-09AAD2CFADA4","rank":"normal"}],"P205":[{"mainsnak":{"snaktype":"value","property":"P205","hash":"11d242c079fdb0792b4ad240f89f7b8799f64e7c","datavalue":{"value":"https://doi.org/10.1023/a:1008224928678","type":"string"},"datatype":"url"},"type":"statement","id":"Q1369725$02C8F908-917A-40F7-BB81-8CD34722651C","rank":"normal"}],"P388":[{"mainsnak":{"snaktype":"value","property":"P388","hash":"ef08d06ea15035e43a48fca97c87de74d3025a4c","datavalue":{"value":"W2127067821","type":"string"},"datatype":"external-id"},"type":"statement","id":"Q1369725$2E4F6AA3-8CF1-41E5-824B-C4B6438E0EAE","rank":"normal"}],"P1643":[{"mainsnak":{"snaktype":"value","property":"P1643","hash":"9ae7890a10932354157fceee4f28e662d8239ea1","datavalue":{"value":{"entity-type":"item","numeric-id":1849601,"id":"Q1849601"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","qualifiers":{"P1659":[{"snaktype":"value","property":"P1659","hash":"f277f191f2a3a879a9f2fb563643188ffff2872c","datavalue":{"value":{"amount":"+0.8185720443725586","unit":"1"},"type":"quantity"},"datatype":"quantity"}],"P1660":[{"snaktype":"value","property":"P1660","hash":"a327a09ea0305e98d5cf33bd4036320e19f2aed0","datavalue":{"value":{"entity-type":"item","numeric-id":6821328,"id":"Q6821328"},"type":"wikibase-entityid"},"datatype":"wikibase-item"}]},"qualifiers-order":["P1659","P1660"],"id":"Q1369725$B3E5B5A2-B111-4278-8D2B-F1C468CA9CF7","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1643","hash":"72a7bb585ee6b33b00b7b9425b98cd35229fd233","datavalue":{"value":{"entity-type":"item","numeric-id":3593108,"id":"Q3593108"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","qualifiers":{"P1659":[{"snaktype":"value","property":"P1659","hash":"0558b02c1ef9a8001425ce1b54bd1b069f78eae1","datavalue":{"value":{"amount":"+0.7944247722625732","unit":"1"},"type":"quantity"},"datatype":"quantity"}],"P1660":[{"snaktype":"value","property":"P1660","hash":"a327a09ea0305e98d5cf33bd4036320e19f2aed0","datavalue":{"value":{"entity-type":"item","numeric-id":6821328,"id":"Q6821328"},"type":"wikibase-entityid"},"datatype":"wikibase-item"}]},"qualifiers-order":["P1659","P1660"],"id":"Q1369725$EDF1E637-638C-446E-9BB7-EE774B7AF4BE","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1643","hash":"9a8256af6fcb3afeeff790206d7165a0858f4bbe","datavalue":{"value":{"entity-type":"item","numeric-id":5429411,"id":"Q5429411"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","qualifiers":{"P1659":[{"snaktype":"value","property":"P1659","hash":"2861b268337cf9f05f28acaf3d04974651b63b22","datavalue":{"value":{"amount":"+0.7772336006164551","unit":"1"},"type":"quantity"},"datatype":"quantity"}],"P1660":[{"snaktype":"value","property":"P1660","hash":"a327a09ea0305e98d5cf33bd4036320e19f2aed0","datavalue":{"value":{"entity-type":"item","numeric-id":6821328,"id":"Q6821328"},"type":"wikibase-entityid"},"datatype":"wikibase-item"}]},"qualifiers-order":["P1659","P1660"],"id":"Q1369725$EE83F963-7999-4887-9C5D-13CC1FCEB6FC","rank":"normal"},{"mainsnak":{"snaktype":"value","property":"P1643","hash":"bd4cf0ad59b02cca3b53a65d4d818725f8ad74a0","datavalue":{"value":{"entity-type":"item","numeric-id":4639335,"id":"Q4639335"},"type":"wikibase-entityid"},"datatype":"wikibase-item"},"type":"statement","qualifiers":{"P1659":[{"snaktype":"value","property":"P1659","hash":"c5fca6d6100e126a7c8169fa94236961566fb0f6","datavalue":{"value":{"amount":"+0.7731503844261169","unit":"1"},"type":"quantity"},"datatype":"quantity"}],"P1660":[{"snaktype":"value","property":"P1660","hash":"a327a09ea0305e98d5cf33bd4036320e19f2aed0","datavalue":{"value":{"entity-type":"item","numeric-id":6821328,"id":"Q6821328"},"type":"wikibase-entityid"},"datatype":"wikibase-item"}]},"qualifiers-order":["P1659","P1660"],"id":"Q1369725$0E1BD92D-CFD5-421C-B86F-6CE6CD1BE186","rank":"normal"}]},"sitelinks":{"mardi":{"site":"mardi","title":"On weaknesses of non-surjective round functions","badges":[],"url":"https://portal.mardi4nfdi.de/wiki/On_weaknesses_of_non-surjective_round_functions"}}}}}