Pseudorandomness analysis of the (extended) Lai-Massey scheme. (English) Zbl 1260.94048
Summary: In this paper we find that the two-round (extended) Lai-Massey scheme is not pseudorandom and three-round (extended) Lai-Massey scheme is not strong pseudorandom. Combined with previous work, we prove that three rounds are necessary and sufficient for the pseudorandomness and four rounds are necessary and sufficient for the strong pseudorandomness.

94A60 Cryptography
68P30 Coding and information theory (compaction, compression, models of communication, encoding schemes, etc.) (aspects in computer science)
