Eliminating Random Permutation Oracles in the Even-Mansour Cipher


Even and Mansour [EM97] proposed a block cipher construction that takes a publicly computable random permutation oracle P and XORs different keys prior to and after applying P : C = k2 ⊕P (M ⊕ k1). They did not, however, describe how one could instantiate such a permutation securely. It is a fundamental open problem whether their construction could be… (More)
DOI: 10.1007/978-3-540-30539-2_3

