Abstract:
We calculate the means of Patarin statistics that are used in distinguishing CPA-attacks on $3$ and $4$ rounds of the Luby — Rackoff scheme. We study a model of independent permutations and make two queries for each. In this model, we find estimates of error probabilities and explicit expressions for the data complexities of attacks based on similar statistics. In case of $4$ rounds and block lengths $16$–$52$ we have got empirical error probabilities in the model of independent permutations and in the model of queries for a single permutation.