#StackBounty: #pseudo-random-function on CPA & KPA security of $boxplus$-Feistel

Bounty: 50

I am interested to identify the effect of replacing $oplus$ with $boxplus$ on basic balanced Feistel structure over $r$-rounds. Given;

$F_boxplus[L,R]= [S,T] = [R,L boxplus f(R)]$ where $f$ is PRF

$[L,R] in left{0,1right} ^{n} $

Q1 . In term of CPA and KPA security, does $boxplus$ replacement add security over 3 rounds, with proof?

Q2 . If $boxplus$-Feistel structure have better security bounds that $oplus$-Feistel, why do not we see it common?

Get this bounty!!!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.