❚✇❡❛❦❛❜❧❡ ❇❧♦❝❦❝✐♣❤❡rs ❛♥❞ ❇❡②♦♥❞ ❇✐rt❤❞❛② ❇♦✉♥❞ ❙❡❝✉r✐t②
❇❛rt ▼❡♥♥✐♥❦ ❘❛❞❜♦✉❞ ❯♥✐✈❡rs✐t② ✭❚❤❡ ◆❡t❤❡r❧❛♥❞s✮ ✽t❤ ❆s✐❛♥ ❲♦r❦s❤♦♣ ♦♥ ❙②♠♠❡tr✐❝ ❑❡② ❈r②♣t♦❣r❛♣❤② ◆♦✈❡♠❜❡r ✶✺✱ ✷✵✶✽
✶ ✴ ✹✽
rs - - PowerPoint PPT Presentation
rs rt rt rt rst
✶ ✴ ✹✽
✷ ✴ ✹✽
✷ ✴ ✹✽
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E
N,tA1 k
˜ E
N,tA2 k
˜ E
N,tAa k
˜ E
N,tM⊕ k
˜ E
N,tM1 k
˜ E
N,tM2 k
˜ E
N,tMd k
❚✇❡❛❦ ✐s ✉♥✐q✉❡ ❢♦r ❡✈❡r② ❡✈❛❧✉❛t✐♦♥ ❉✐✛❡r❡♥t ❜❧♦❝❦s ❛❧✇❛②s tr❛♥s❢♦r♠❡❞ ✉♥❞❡r ❞✐✛❡r❡♥t t✇❡❛❦
✸ ✴ ✹✽
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E
N,tA1 k
˜ E
N,tA2 k
˜ E
N,tAa k
˜ E
N,tM⊕ k
˜ E
N,tM1 k
˜ E
N,tM2 k
˜ E
N,tMd k
✸ ✴ ✹✽
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E
N,tA1 k
˜ E
N,tA2 k
˜ E
N,tAa k
˜ E
N,tM⊕ k
˜ E
N,tM1 k
˜ E
N,tM2 k
˜ E
N,tMd k
✸ ✴ ✹✽
t
E
P
✹ ✴ ✹✽
✜rst r♦✉♥❞✱ s❡❝♦♥❞ r♦✉♥❞✱ t❤✐r❞ r♦✉♥❞✱ ✜♥❛❧ r♦✉♥❞
t
E
P
✹ ✴ ✹✽
✜rst r♦✉♥❞✱ s❡❝♦♥❞ r♦✉♥❞✱ t❤✐r❞ r♦✉♥❞✱ ✜♥❛❧ r♦✉♥❞
✺ ✴ ✹✽
IC
distinguisher D
tweakable blockcipher random tweakable permutation
✻ ✴ ✹✽
IC
distinguisher D
tweakable blockcipher random tweakable permutation
E−1
k
π, π−1 = 1
✼ ✴ ✹✽
✽ ✴ ✹✽
✾ ✴ ✹✽
✾ ✴ ✹✽
✶✵ ✴ ✹✽
✶✵ ✴ ✹✽
✶✵ ✴ ✹✽
❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②
✶✶ ✴ ✹✽
Ek(t, m) = Ek(t ⊕ C, m ⊕ C)
❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②
✶✶ ✴ ✹✽
Ek(t, m) = Ek(t ⊕ C, m ⊕ C)
❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②
✶✶ ✴ ✹✽
Ek(t, m) = Ek(t ⊕ C, m ⊕ C)
k
❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②
✶✶ ✴ ✹✽
Ek(t, m) = Ek(t ⊕ C, m ⊕ C)
k
E−1
k (t, c) ⊕
E−1
k (t ⊕ C, c) = h ⊗ C
❚✇♦✲s✐❞❡❞ ♠❛s❦✐♥❣ ♥❡❝❡ss❛r②
✶✶ ✴ ✹✽
Ek(t, m) = Ek(t ⊕ C, m ⊕ C)
k
E−1
k (t, c) ⊕
E−1
k (t ⊕ C, c) = h ⊗ C
✶✶ ✴ ✹✽
✶✷ ✴ ✹✽
✶✷ ✴ ✹✽
✶✷ ✴ ✹✽
✶✷ ✴ ✹✽
✶✷ ✴ ✹✽
❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s ♥❡❡❞ ❛t ♠♦st❄
❇♦✐❧s ❞♦✇♥ t♦ ✜♥❞✐♥❣ ❣❡♥❡r✐❝ ❛tt❛❝❦s
❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s ♥❡❡❞ ❛t ❧❡❛st❄
❇♦✐❧s ❞♦✇♥ t♦ ♣r♦✈❛❜❧❡ s❡❝✉r✐t②
✶✸ ✴ ✹✽
❍♦✇ ♠❛♥② ❡✈❛❧✉❛t✐♦♥s ❞♦❡s ♥❡❡❞ ❛t ❧❡❛st❄
❇♦✐❧s ❞♦✇♥ t♦ ♣r♦✈❛❜❧❡ s❡❝✉r✐t②
✶✸ ✴ ✹✽
✶✸ ✴ ✹✽
✶✹ ✴ ✹✽
✶✹ ✴ ✹✽
✶✹ ✴ ✹✽
✶✹ ✴ ✹✽
✶✹ ✴ ✹✽
❈♦♥s✐❞❡r ❛♥② tr❛♥s❝r✐♣t ❛♥ ❛❞✈❡rs❛r② ♠❛② s❡❡ ▼♦st ✬s s❤♦✉❧❞ ❜❡ ❡q✉❛❧❧② ❧✐❦❡❧② ✐♥ ❜♦t❤ ✇♦r❧❞s ❖❞❞ ♦♥❡s s❤♦✉❧❞ ❤❛♣♣❡♥ ✇✐t❤ ✈❡r② s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②
✶✺ ✴ ✹✽
✶✺ ✴ ✹✽
✶✺ ✴ ✹✽
✶✻ ✴ ✹✽
m c tweak-based mask
m c tweak-based mask
✶✼ ✴ ✹✽
m c tweak-based mask
m c tweak-based mask
✶✼ ✴ ✹✽
m c t
m c h(t)
✶✽ ✴ ✹✽
m c 2α3β7γ · Ek(N)
✶✾ ✴ ✹✽
m c 2α3β7γ · Ek(N)
✶✾ ✴ ✹✽
m c 2α3β7γ · Ek(N)
m c 2α3β7γ · (kN ⊕ P(kN))
✶✾ ✴ ✹✽
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T ˜ E
N,tA1 k
˜ E
N,tA2 k
˜ E
N,tAa k
˜ E
N,tM⊕ k
˜ E
N,tM1 k
˜ E
N,tM2 k
˜ E
N,tMd k
❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
✷✵ ✴ ✹✽
L = Ek(N)
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T
2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL
Ek Ek Ek Ek Ek Ek Ek
❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
✷✵ ✴ ✹✽
L = Ek(N)
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T
2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL
Ek Ek Ek Ek Ek Ek Ek
❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
✷✵ ✴ ✹✽
L = Ek(N)
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T
2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL
Ek Ek Ek Ek Ek Ek Ek
❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
✷✵ ✴ ✹✽
L = Ek(N)
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T
2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL
Ek Ek Ek Ek Ek Ek Ek
❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
✷✵ ✴ ✹✽
L = Ek(N)
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T
2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL
Ek Ek Ek Ek Ek Ek Ek
❙❤✐❢t ❛♥❞ ❝♦♥❞✐t✐♦♥❛❧ ❳❖❘
✷✵ ✴ ✹✽
L = Ek(N)
A1 A2 Aa M1 M2 Md ⊕Mi C1 C2 Cd T
2·32L 2232L 2a32L 2d3L 2L 22L 2dL 2L 22L 2dL
Ek Ek Ek Ek Ek Ek Ek
✷✵ ✴ ✹✽
L = Ek(N)
m c
❙✐♥❣❧❡ ❳❖❘ ▲♦❣❛r✐t❤♠✐❝ ❛♠♦✉♥t ♦❢ ✜❡❧❞ ❞♦✉❜❧✐♥❣s ✭♣r❡❝♦♠♣✉t❡❞✮
✷✶ ✴ ✹✽
m c
✷✶ ✴ ✹✽
✷✷ ✴ ✹✽
m c ϕγ
2 ◦ ϕβ 1 ◦ ϕα 0 ◦ P(Nk)
P♦✇❡r✐♥❣✲✉♣ ♠❛s❦✐♥❣ ❲♦r❞✲❜❛s❡❞ ▲❋❙❘s
✷✸ ✴ ✹✽
m c ϕγ
2 ◦ ϕβ 1 ◦ ϕα 0 ◦ P(Nk)
✷✸ ✴ ✹✽
m c ϕγ
2 ◦ ϕβ 1 ◦ ϕα 0 ◦ P(Nk)
✷✸ ✴ ✹✽
✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳
✷✹ ✴ ✹✽
b w n ϕ 128 8 16 (x1, . . . , x15, (x0 ≪ 1) ⊕ (x9 ≫ 1) ⊕ (x10 ≪ 1)) 128 32 4 (x1, . . . , x3, (x0 ≪ 5) ⊕ x1 ⊕ (x1 ≪ 13)) 128 64 2 (x1, (x0 ≪ 11) ⊕ x1 ⊕ (x1 ≪ 13)) 256 64 4 (x1, . . . , x3, (x0 ≪ 3) ⊕ (x3 ≫ 5)) 512 32 16 (x1, . . . , x15, (x0 ≪ 5) ⊕ (x3 ≫ 7)) 512 64 8 (x1, . . . , x7, (x0 ≪ 29) ⊕ (x1 ≪ 9)) 1024 64 16 (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13)) 1600 32 50 (x1, . . . , x49, (x0 ≪ 3) ⊕ (x23 ≫ 3)) ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳
✷✹ ✴ ✹✽
b w n ϕ 128 8 16 (x1, . . . , x15, (x0 ≪ 1) ⊕ (x9 ≫ 1) ⊕ (x10 ≪ 1)) 128 32 4 (x1, . . . , x3, (x0 ≪ 5) ⊕ x1 ⊕ (x1 ≪ 13)) 128 64 2 (x1, (x0 ≪ 11) ⊕ x1 ⊕ (x1 ≪ 13)) 256 64 4 (x1, . . . , x3, (x0 ≪ 3) ⊕ (x3 ≫ 5)) 512 32 16 (x1, . . . , x15, (x0 ≪ 5) ⊕ (x3 ≫ 7)) 512 64 8 (x1, . . . , x7, (x0 ≪ 29) ⊕ (x1 ≪ 9)) 1024 64 16 (x1, . . . , x15, (x0 ≪ 53) ⊕ (x5 ≪ 13)) 1600 32 50 (x1, . . . , x49, (x0 ≪ 3) ⊕ (x23 ≫ 3)) ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳ ✳
✷✹ ✴ ✹✽
2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′
✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹
s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪ r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱ ❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪
✷✺ ✴ ✹✽
2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′
✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹
s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪ r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱ ❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪
✷✺ ✴ ✹✽
2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′
✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹
s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪ r❡s✉❧ts ✐♠♣❧✐❝✐t❧② ✉s❡❞✱ ❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪
✷✺ ✴ ✹✽
2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′
✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹
s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪
❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮ s♦❧✈❡❞ ❜② ●r❛♥❣❡r ❡t ❛❧✳ ❬●❏▼◆✶✻❪
✷✺ ✴ ✹✽
2 ◦ ϕβ 1 ◦ ϕα 0 = ϕγ′ 2 ◦ ϕβ′ 1 ◦ ϕα′
✻✹ ✶✷✽ ✷✺✻ ✺✶✷ ✶✵✷✹
s♦❧✈❡❞ ❜② ❘♦❣❛✇❛② ❬❘♦❣✵✹❪
❡✳❣✳✱ ❜② Prøst ✭✷✵✶✹✮
✷✺ ✴ ✹✽
A0 A1 Aa–1 M0 M1 Md–1 ⊕Mi C1 C2 Cd T
ϕ0(L) ϕ0(L) ϕ1(L) ϕ1(L) ϕa–1(L) ϕa–1(L) ϕ2◦ϕ2
1◦ϕd–1(L)
ϕ2◦ϕ2
1◦ϕd–1(L)
ϕ2◦ϕ0(L) ϕ2◦ϕ1(L) ϕ2◦ϕd–1(L) ϕ2◦ϕ0(L) ϕ2◦ϕ1(L) ϕ2◦ϕd–1(L)
P P P P P P P
✷✻ ✴ ✹✽
L = P(Nk) ϕ1 = ϕ ⊕ id, ϕ2 = ϕ2 ⊕ ϕ ⊕ id
A0 Aa–1 T0 Td–1 M0 Md–1
|A||M|
C1 Cd T
ϕ0(L) ϕ0(L) ϕa–1(L) ϕa–1(L) ϕ1◦ϕ0(L) ϕ1◦ϕ0(L) ϕ1◦ϕd–1(L) ϕ1◦ϕd–1(L) ϕ2
1(L)
ϕ2
1(L)
ϕ2(L) ϕ2(L) ϕ2(L)⊕M0 ϕ2(L)⊕Md–1
P P P P P P P
✷✼ ✴ ✹✽
L = P(Nk) ϕ1 = ϕ ⊕ id, ϕ2 = ϕ2 ⊕ ϕ ⊕ id
✷✽ ✴ ✹✽
❚✇❡❛❦✲r❡❦❡②✐♥❣ ❬▼✐♥✵✾✱▼❡♥✶✺✱❲●❩✰✶✻✱❏▲▼✰✶✼✱▲▲✶✽❪ ❈❛s❝❛❞✐♥❣ ✭♥♦✇✮
✷✾ ✴ ✹✽
✷✾ ✴ ✹✽
m c
· · · · · ·
h1(t) h1(t)⊕h2(t) hρ−1(t)⊕hρ(t) hρ(t)
✸✵ ✴ ✹✽
✏❈❛s❝❛❞❡❞ LRW2✑ ❂ LRW2[2]
m c
· · · · · ·
h1(t) h1(t)⊕h2(t) hρ−1(t)⊕hρ(t) hρ(t)
✸✵ ✴ ✹✽
✏❈❛s❝❛❞❡❞ LRW2✑ ❂ LRW2[2]
m c
· · · · · ·
h1(t) h1(t)⊕h2(t) hρ−1(t)⊕hρ(t) hρ(t)
✸✶ ✴ ✹✽
m c
· · · · · ·
h1(t) h1(t)⊕h2(t) hρ−1(t)⊕hρ(t) hρ(t)
✸✶ ✴ ✹✽
n/2 2n/3 3n/4 5n/6 n LRW2[1] LRW2[2] LRW2[3] LRW2[4] LRW2[5] LRW2[6] LRW2[7] LRW2[8] LRW2[9] LRW2[10] LRW2[11] ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ n/2 2n/3 3n/4 5n/6 n TEM[1] TEM[2] TEM[3] TEM[4] TEM[5] TEM[6] TEM[7] TEM[8] TEM[9] TEM[10] TEM[11] ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣
✸✷ ✴ ✹✽
n/2 2n/3 3n/4 5n/6 n LRW2[1] LRW2[2] LRW2[3] LRW2[4] LRW2[5] LRW2[6] LRW2[7] LRW2[8] LRW2[9] LRW2[10] LRW2[11] ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ n/2 2n/3 3n/4 5n/6 n TEM[1] TEM[2] TEM[3] TEM[4] TEM[5] TEM[6] TEM[7] TEM[8] TEM[9] TEM[10] TEM[11] ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣ ❣❛♣
✸✷ ✴ ✹✽
✸✸ ✴ ✹✽
m Ek1 Ek2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ ✕
✸✹ ✴ ✹✽
m Ek1 Ek2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ ✕
✸✹ ✴ ✹✽
m Ek1 Ek2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ ✕
✸✹ ✴ ✹✽
m Ek1 Ek2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ LRW2[3]✕LRW2[5]
✸✹ ✴ ✹✽
✸✺ ✴ ✹✽
m Ek1 Ek2 c
f1(t) f2(t) f3(t)
✸✻ ✴ ✹✽
m Ek1 Ek2 c
f1(t) f2(t) f3(t)
✸✻ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
✸✼ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 ⊕ f1(t′)
2 ⊕ f3(t′) = c3 ⊕ f3(t)
4 ⊕ f1(t′)
✸✼ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 ⊕ f1(t′)
2 ⊕ f3(t′) = c3 ⊕ f3(t)
4 ⊕ f1(t′)
4 ⊕ f3(t′)
✸✼ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 ⊕ f1(t′)
2 ⊕ f3(t′) = c3 ⊕ f3(t)
4 ⊕ f1(t′)
4 ⊕ f3(t′)
2 = m3 ⊕ m′ 4 = f1(t) ⊕ f1(t′)
2 ⊕ c3 = c1 ⊕ c′ 4 = f3(t) ⊕ f3(t′)
✸✼ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 = m3 ⊕ m′ 4 = f1(t) ⊕ f1(t′)
2 ⊕ c3 = c1 ⊕ c′ 4 = f3(t) ⊕ f3(t′)
✸✽ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 = m3 ⊕ m′ 4 = f1(t) ⊕ f1(t′)
2 ⊕ c3 = c1 ⊕ c′ 4 = f3(t) ⊕ f3(t′)
✸✽ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 = m3 ⊕ m′ 4 = f1(t) ⊕ f1(t′)
2 ⊕ c3 = c1 ⊕ c′ 4 = f3(t) ⊕ f3(t′)
i✬s s✉❝❤ t❤❛t
2 = m3 ⊕ m′ 4 = d
✸✽ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 = m3 ⊕ m′ 4 = f1(t) ⊕ f1(t′)
2 ⊕ c3 = c1 ⊕ c′ 4 = f3(t) ⊕ f3(t′)
i✬s s✉❝❤ t❤❛t
2 = m3 ⊕ m′ 4 = d
2 ⊕ c3 = c1 ⊕ c′ 4]❄
✸✽ ✴ ✹✽
m1 m3 m′
2
m′
4
p1 p1 p1 p1 p2 p2 p2 p2 c1 c3 c′
2
c′
4 f1(t) f1(t′) f2(t) f2(t′) f3(t) f3(t′)
2 = m3 ⊕ m′ 4 = f1(t) ⊕ f1(t′)
2 ⊕ c3 = c1 ⊕ c′ 4 = f3(t) ⊕ f3(t′)
i✬s s✉❝❤ t❤❛t
2 = m3 ⊕ m′ 4 = d
2 ⊕ c3 = c1 ⊕ c′ 4]❄
✸✽ ✴ ✹✽
Ek = 1
π = 1
✐♥ r❡❛❧ ✇♦r❧❞ ❢♦r ✐♥ ✐❞❡❛❧ ✇♦r❧❞ ❢♦r r❛♥❞♦♠ r❛♥❞♦♠
✸✾ ✴ ✹✽
Ek = 1
π = 1
2 ⊕ c3 = c1 ⊕ c′ 4 Nd ✐♥ r❡❛❧ ✇♦r❧❞ ❢♦r d = Nd ✐♥ ✐❞❡❛❧ ✇♦r❧❞ ❢♦r d = n n1/2 ≈ q f1(t) ⊕ f1(t′) r❛♥❞♦♠ f1(t) ⊕ f1(t′) r❛♥❞♦♠ 16 2 4 · 212 256.593750 129.781250 127.093750 127.375000 20 2 4 · 215 265.531250 133.312500 125.625000 128.750000 24 2 4 · 218 246.750000 131.375000 120.625000 129.875000
✸✾ ✴ ✹✽
✹✵ ✴ ✹✽
m Ek1 Ek2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✹✶ ✴ ✹✽
m Ek1 Ek2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✹✶ ✴ ✹✽
m p1 p2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✹✷ ✴ ✹✽
m p1 p2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
✹✷ ✴ ✹✽
m p1 p2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
m ⊕ h1(t) c ⊕ h2(t) h1(t) ⊕ h2(t)
✹✸ ✴ ✹✽
m p1 p2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
m ⊕ h1(t) c ⊕ h2(t) h1(t) ⊕ h2(t)
2 (c ⊕ h2(t))
✹✸ ✴ ✹✽
m p1 p2 c
h1(t) h1(t) ⊕ h2(t) h2(t)
m ⊕ h1(t) c ⊕ h2(t) h1(t) ⊕ h2(t)
2 (c ⊕ h2(t))
✹✸ ✴ ✹✽
¯ m1 ¯ m2 = ¯ m3 ¯ m4 = ¯ m5 = ¯ m6 ¯ m7 ¯ c1 ¯ c2 ¯ c3 ¯ c4 ¯ c5 ¯ c6 = ¯ c7 f(t1) f(t2) f(t3) f(t4) f(t5) f2(t6) f2(t7)
♥♦t❛t✐♦♥✿ ¯ mi ❂ mi ⊕ h1(ti) ¯ ci ❂ ci ⊕ h2(ti) f(ti) ❂ h1(ti) ⊕ h2(ti)
✭✐✮ ●r❛♣❤ ❝♦♥t❛✐♥s ❝✐r❝❧❡ ✭✐✐✮ ●r❛♣❤ ❝♦♥t❛✐♥s ♣❛t❤ ♦❢ ❡✈❡♥ ❧❡♥❣t❤ ✇❤♦s❡ ❧❛❜❡❧s s✉♠ t♦ ✭❞❡❣❡♥❡r❛❝②✮
✹✹ ✴ ✹✽
¯ m1 ¯ m2 = ¯ m3 ¯ m4 = ¯ m5 = ¯ m6 ¯ m7 ¯ c1 ¯ c2 ¯ c3 ¯ c4 ¯ c5 ¯ c6 = ¯ c7 f(t1) f(t2) f(t3) f(t4) f(t5) f2(t6) f2(t7)
♥♦t❛t✐♦♥✿ ¯ mi ❂ mi ⊕ h1(ti) ¯ ci ❂ ci ⊕ h2(ti) f(ti) ❂ h1(ti) ⊕ h2(ti)
✭✐✮ ●r❛♣❤ ❝♦♥t❛✐♥s ❝✐r❝❧❡ ✭✐✐✮ ●r❛♣❤ ❝♦♥t❛✐♥s ♣❛t❤ ♦❢ ❡✈❡♥ ❧❡♥❣t❤ ✇❤♦s❡ ❧❛❜❡❧s s✉♠ t♦ 0 ✭❞❡❣❡♥❡r❛❝②✮
✹✹ ✴ ✹✽
¯ m1 ¯ m2 = ¯ m3 ¯ m4 = ¯ m5 = ¯ m6 ¯ m7 ¯ c1 ¯ c2 ¯ c3 ¯ c4 ¯ c5 ¯ c6 = ¯ c7 f(t1) f(t2) f(t3) f(t4) f(t5) f2(t6) f2(t7)
♥♦t❛t✐♦♥✿ ¯ mi ❂ mi ⊕ h1(ti) ¯ ci ❂ ci ⊕ h2(ti) f(ti) ❂ h1(ti) ⊕ h2(ti)
✭✐✮ ●r❛♣❤ ❝♦♥t❛✐♥s ❝✐r❝❧❡ ✭✐✐✮ ●r❛♣❤ ❝♦♥t❛✐♥s ♣❛t❤ ♦❢ ❡✈❡♥ ❧❡♥❣t❤ ✇❤♦s❡ ❧❛❜❡❧s s✉♠ t♦ 0 ✭❞❡❣❡♥❡r❛❝②✮
✹✹ ✴ ✹✽
✹✺ ✴ ✹✽
✹✺ ✴ ✹✽
✹✺ ✴ ✹✽
✹✻ ✴ ✹✽
✹✼ ✴ ✹✽
✹✽ ✴ ✹✽
✹✽ ✴ ✹✽
✹✾ ✴ ✹✽
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ ✲
✺✵ ✴ ✹✽
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ ✲
✺✵ ✴ ✹✽
✐♠♣r♦✈❡❞ ❛tt❛❝❦ ✭❣❡♥❡r❛❧✐③❡❞ ❝♦♥str✉❝t✐♦♥✮ ✐♠♣r♦✈❡❞ ❜♦✉♥❞ ✭❝♦♥❞✐t✐♦♥❛❧❧②✮ ❝❛rr✐❡s ♦✈❡r t♦ LRW2[3]✲LRW2[5]
✺✵ ✴ ✹✽
❊❛❝❤ ❝♦♥✈❡rs❛t✐♦♥ ❞❡✜♥❡s ❛ tr❛♥s❝r✐♣t ❢♦r ♠♦st ♦❢ t❤❡ tr❛♥s❝r✐♣ts ❘❡♠❛✐♥✐♥❣ tr❛♥s❝r✐♣ts ♦❝❝✉r ✇✐t❤ s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②
✺✶ ✴ ✹✽
IC
O P
distinguisher D
❊❛❝❤ ❝♦♥✈❡rs❛t✐♦♥ ❞❡✜♥❡s ❛ tr❛♥s❝r✐♣t ❢♦r ♠♦st ♦❢ t❤❡ tr❛♥s❝r✐♣ts ❘❡♠❛✐♥✐♥❣ tr❛♥s❝r✐♣ts ♦❝❝✉r ✇✐t❤ s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②
✺✶ ✴ ✹✽
IC
O P
distinguisher D
❢♦r ♠♦st ♦❢ t❤❡ tr❛♥s❝r✐♣ts ❘❡♠❛✐♥✐♥❣ tr❛♥s❝r✐♣ts ♦❝❝✉r ✇✐t❤ s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②
✺✶ ✴ ✹✽
IC
O P
distinguisher D
❘❡♠❛✐♥✐♥❣ tr❛♥s❝r✐♣ts ♦❝❝✉r ✇✐t❤ s♠❛❧❧ ♣r♦❜❛❜✐❧✐t②
✺✶ ✴ ✹✽
IC
O P
distinguisher D
✺✶ ✴ ✹✽
✺✷ ✴ ✹✽
✺✷ ✴ ✹✽
✺✷ ✴ ✹✽
✺✷ ✴ ✹✽
✺✸ ✴ ✹✽
✺✸ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦P ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦Pd ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦Pd ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
❆✉t❤♦rs P✉❜❧✐❝❛t✐♦♥ ❆♣♣❧✐❝❛t✐♦♥ ▼✐rr♦r ❇♦✉♥❞ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✸ ❋❡✐st❡❧ ❙✉❜♦♣t✐♠❛❧ P❛t❛r✐♥ ❈❘❨P❚❖ ✷✵✵✹ ❋❡✐st❡❧ P❛t❛r✐♥ ■❈■❙❈ ✷✵✵✺ ❋❡✐st❡❧ ❖♣t✐♠❛❧ ✐♥ O(·) P❛t❛r✐♥✱ ▼♦♥tr❡✉✐❧ ■❈■❙❈ ✷✵✵✺ ❇❡♥❡s P❛t❛r✐♥ ■❈■❚❙ ✷✵✵✽ ❳♦P P❛t❛r✐♥ ❆❋❘■❈❆❈❘❨P❚ ✷✵✵✽ ❇❡♥❡s P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✽✼ ❳♦P ❈♦♥❝r❡t❡ ❜♦✉♥❞ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✵✴✷✾✸ ❋❡✐st❡❧ P❛t❛r✐♥ ❡Pr✐♥t ✷✵✶✸✴✸✻✽ ❳♦P ❈♦❣❧✐❛t✐✱ ▲❛♠♣❡✱ P❛t❛r✐♥ ❋❙❊ ✷✵✶✹ ❳♦Pd ❱♦❧t❡✱ ◆❛❝❤❡❢✱ ▼❛rr✐èr❡ ❡Pr✐♥t ✷✵✶✻✴✶✸✻ ❋❡✐st❡❧ ■✇❛t❛✱ ▼❡♥♥✐♥❦✱ ❱✐③ár ❡Pr✐♥t ✷✵✶✻✴✶✵✽✼ ❈❊◆❈
✺✹ ✴ ✹✽
Pa1 =Pa2 Pb1 Pb3 Pa4 =Pa5 Pb5 Pb2 =Pa3 =Pb4
λ1 λ2 λ3 λ4 λ5
Pa6 Pb6
λ6
Pa7 Pb7
λ7
Pa8 Pa9 Pb8 =Pb9 =Pb10 =Pa11 Pa10 Pb11
λ8 λ9 λ10 λ11 ✺✺ ✴ ✹✽
✺✻ ✴ ✹✽
Pa Pb Pc
λ1 λ2
✺✻ ✴ ✹✽
Pa Pb Pc
λ1 λ2
✺✻ ✴ ✹✽
Pa Pb Pc
λ1 λ2
✺✻ ✴ ✹✽
Pa Pb Pc
λ1 λ2
✺✻ ✴ ✹✽
Pa Pb Pc
λ1 λ2
✺✼ ✴ ✹✽
Pa Pb Pc Pd
λ1 λ2
✺✼ ✴ ✹✽
Pa Pb Pc Pd
λ1 λ2
✺✼ ✴ ✹✽
Pa Pb Pc Pd
λ1 λ2
✺✼ ✴ ✹✽
Pa Pb Pc Pd
λ1 λ2
✺✼ ✴ ✹✽
Pa Pb Pc Pd
λ1 λ2
✺✽ ✴ ✹✽
Pa Pb Pc
λ1 λ2 λ3
✺✽ ✴ ✹✽
Pa Pb Pc
λ1 λ2 λ3
✺✽ ✴ ✹✽
Pa Pb Pc
λ1 λ2 λ3
Pa1 = Pb5 Pb1 = Pa2 Pb2 = Pa3 Pb3 = Pa4 Pb4 = Pa5
λ1 λ2 λ3 λ4 λ5
Pa1 =Pa2 Pb1 Pa3 =Pa4 Pb4 = Pa5 Pb2 =Pb3
λ1 λ2 λ3 λ4
Pa8 Pb7 = Pb8
λ1 ⊕ λ2 ⊕ · · · ⊕ λ7
Pb5 = Pa6 Pb6 = Pb7
λ6 λ5 λ7 ✺✾ ✴ ✹✽
✻✵ ✴ ✹✽
1· 0·
✻✶ ✴ ✹✽
1· 0·
✻✶ ✴ ✹✽
1· 0·
✻✶ ✴ ✹✽
1· 0·
✻✶ ✴ ✹✽
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
❈❛❧❧ t❤✐s ❛ ❜❛❞ tr❛♥s❝r✐♣t
✻✷ ✴ ✹✽
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
− → ❈❛❧❧ t❤✐s ❛ ❜❛❞ tr❛♥s❝r✐♣t
✻✷ ✴ ✹✽
Pa1 Pb1 Pa2 Pb2 Paq Pbq · · ·
y1 y2 yq
− → ❈❛❧❧ t❤✐s ❛ ❜❛❞ tr❛♥s❝r✐♣t
2nq
✻✷ ✴ ✹✽
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
❜❛❞ tr❛♥s❝r✐♣t ❢♦r
❣✐✈❡s ❣✐✈❡s
✻✸ ✴ ✹✽
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
❣✐✈❡s ❣✐✈❡s
✻✸ ✴ ✹✽
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
·
1 (2n)2q
❣✐✈❡s
✻✸ ✴ ✹✽
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
·
1 (2n)2q
1 2nq
✻✸ ✴ ✹✽
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
·
1 (2n)2q
1 2nq
✻✸ ✴ ✹✽
XoP(q) ≤ ε + Pr [❜❛❞ tr❛♥s❝r✐♣t ❢♦r f]
2nq
·
1 (2n)2q
1 2nq
XoP(q) ≤ q/2n
✻✸ ✴ ✹✽
h(m)
✻✹ ✴ ✹✽