# #StackBounty: #pseudo-random-function on CPA & KPA security of \$boxplus\$-Feistel

### Bounty: 50

I am interested to identify the effect of replacing $$oplus$$ with $$boxplus$$ on basic balanced Feistel structure over $$r$$-rounds. Given;

$$F_boxplus[L,R]= [S,T] = [R,L boxplus f(R)]$$ where $$f$$ is PRF

$$[L,R] in left{0,1right} ^{n}$$

Q1 . In term of CPA and KPA security, does $$boxplus$$ replacement add security over 3 rounds, with proof?

Q2 . If $$boxplus$$-Feistel structure have better security bounds that $$oplus$$-Feistel, why do not we see it common?

